Weaknesses of type CWE-295

859 results

Validação inadequada de certificado SSL/TLS

A aplicação falha em validar corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de hosts diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação sem ser detectado, comprometendo a confidencialidade e integridade dos dados.

Example

Uma app mobile que desativa a verificação de certificado para 'facilitar testes' acaba em produção; um atacante na mesma rede Wi-Fi intercepta requisições HTTPS para roubar tokens de autenticação ou dados sensíveis sem que a app perceba.

How to mitigate

Sempre validar o certificado do servidor (hostname, cadeia de certificados, data de validade), nunca desabilitar verificações em produção, e usar apenas bibliotecas atualizadas que implementam corretamente as regras de validação de TLS.

CVE-2025-71261HIGHHarvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOSEPSS 0.2%CVE-2026-40970MEDIUMWhen configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting EPSS 0.2%CVE-2026-45745HIGHTermix has improper certificate validation in Electron desktop client that enables MITM credential/token theftEPSS 0.2%CVE-2025-40800CRITICALA vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2412 (All versions < EPSS 0.2%CVE-2022-39334LOWnextcloudcmd incorrectly trusts bad TLS certificatesEPSS 0.2%CVE-2024-41256MEDIUMDefault configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification EPSS 0.2%CVE-2026-90651HIGHSocket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. WheEPSS 0.2%CVE-2026-33753MEDIUMImproper Certificate Validation in rfc3161-clientEPSS 0.2%CVE-2026-24122LOWCosign Certificate Chain Expiry Validation Issue Allows Issuing Certificate Expiry to Be OverlookedEPSS 0.2%CVE-2024-30134MEDIUMHCL Traveler for Microsoft Outlook (HTMO) is susceptible to an application modification vulnerabilityEPSS 0.2%CVE-2025-62375MEDIUMgo-witness Improper Verification of AWS EC2 Identity DocumentsEPSS 0.2%CVE-2026-78489MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper CertificEPSS 0.2%CVE-2026-6731MEDIUMX.509 name constraint bypass via Subject CN treated as a DNS nameEPSS 0.2%CVE-2026-78483MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper CertificEPSS 0.2%CVE-2026-66404MEDIUMDEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on thEPSS 0.2%CVE-2021-20327MEDIUMMongoDB Node.js client side field level encryption library may not be validating KMS certificateEPSS 0.2%CVE-2026-3822HIGHTaipower|Taipower APP(Android) - Improper Certificate ValidationEPSS 0.2%CVE-2025-48393MEDIUMThe server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacEPSS 0.2%CVE-2025-35434LOWCISA Thorium does not validate TLS connections to ElasticsearchEPSS 0.2%CVE-2026-0277MEDIUMPrisma Access Agent: Improper Certificate Validation on iOSEPSS 0.2%