Weaknesses of type CWE-295

859 results

Validação inadequada de certificado SSL/TLS

A aplicação falha em validar corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de hosts diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação sem ser detectado, comprometendo a confidencialidade e integridade dos dados.

Example

Uma app mobile que desativa a verificação de certificado para 'facilitar testes' acaba em produção; um atacante na mesma rede Wi-Fi intercepta requisições HTTPS para roubar tokens de autenticação ou dados sensíveis sem que a app perceba.

How to mitigate

Sempre validar o certificado do servidor (hostname, cadeia de certificados, data de validade), nunca desabilitar verificações em produção, e usar apenas bibliotecas atualizadas que implementam corretamente as regras de validação de TLS.

CVE-2025-40744HIGHA vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 11). Affected applications do not properly validate cEPSS 0.2%CVE-2026-73253CRITICALMongoose: TLS Hostname Verification Bypass via Overly Permissive Wildcard MatchingEPSS 0.2%CVE-2023-6057HIGHInsecure Trust of DSA-Signed Certificates in Bitdefender Total Security HTTPS Scanning (VA-11166)EPSS 0.2%CVE-2025-10495HIGHA potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zone client applicationEPSS 0.2%CVE-2024-41258MEDIUMAn issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing atEPSS 0.2%CVE-2026-22696CRITICALdcap-qvl has Missing Verification for QE IdentityEPSS 0.2%CVE-2025-71261HIGHHarvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOSEPSS 0.2%CVE-2022-39334LOWnextcloudcmd incorrectly trusts bad TLS certificatesEPSS 0.2%CVE-2025-40800CRITICALA vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2412 (All versions < EPSS 0.2%CVE-2026-44213MEDIUMOpenTelemetry.Exporter.Instana bypasses TLS certificate validation when a proxy is configuredEPSS 0.2%CVE-2024-41256MEDIUMDefault configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification EPSS 0.2%CVE-2026-87608HIGHImproper certificate validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to EPSS 0.2%CVE-2024-30134MEDIUMHCL Traveler for Microsoft Outlook (HTMO) is susceptible to an application modification vulnerabilityEPSS 0.2%CVE-2026-67598CRITICALEmlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.phpEPSS 0.2%CVE-2026-48248HIGHOpen ISES Tickets < 3.44.2 Disabled TLS Certificate Verification in incs/login.inc.phpEPSS 0.2%CVE-2026-24122LOWCosign Certificate Chain Expiry Validation Issue Allows Issuing Certificate Expiry to Be OverlookedEPSS 0.2%CVE-2026-33308MEDIUMmod_gnutls missing key purpose check in client certificate verificationEPSS 0.2%CVE-2026-6731MEDIUMX.509 name constraint bypass via Subject CN treated as a DNS nameEPSS 0.2%CVE-2026-84197CRITICALIn Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and oEPSS 0.2%CVE-2025-62375MEDIUMgo-witness Improper Verification of AWS EC2 Identity DocumentsEPSS 0.2%