Weaknesses of type CWE-295

859 results

Validação inadequada de certificado SSL/TLS

A aplicação falha em validar corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou de hosts diferentes. Isso permite ataques man-in-the-middle onde um atacante intercepta a comunicação sem ser detectado, comprometendo a confidencialidade e integridade dos dados.

Example

Uma app mobile que desativa a verificação de certificado para 'facilitar testes' acaba em produção; um atacante na mesma rede Wi-Fi intercepta requisições HTTPS para roubar tokens de autenticação ou dados sensíveis sem que a app perceba.

How to mitigate

Sempre validar o certificado do servidor (hostname, cadeia de certificados, data de validade), nunca desabilitar verificações em produção, e usar apenas bibliotecas atualizadas que implementam corretamente as regras de validação de TLS.

CVE-2026-82955CRITICALIn the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API GaEPSS 0.2%CVE-2025-13052HIGHAn improper certificates validation vulnerability was found in the Notification settings of ADMEPSS 0.2%CVE-2025-10539MEDIUMImproper TLS Certificate Validation RCE via Malicious Update in DeskTime Time Tracking AppEPSS 0.2%CVE-2026-93601LOWrustls webpki 0.101.0 before 0.103.12 Name Constraint BypassEPSS 0.2%CVE-2026-93600LOWrustls webpki Name Constraints URI Validation BypassEPSS 0.2%CVE-2025-11695HIGHConfiguration may unexpectedly disable certificate validationEPSS 0.2%CVE-2026-79642MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper CertificEPSS 0.2%CVE-2026-78323MEDIUMJss: jss: jsstrustmanager does not verify nss trust flags on ca certificatesEPSS 0.2%CVE-2025-70045HIGHAn issue pertaining to CWE-295: Improper Certificate Validation was discovered in jxcore jxm master. The application disables TLS/SSL certifEPSS 0.2%CVE-2025-70058HIGHAn issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application disables TLS/SSL certifEPSS 0.2%CVE-2022-34404MEDIUM Dell System Update, version 2.0.0 and earlier, contains an Improper Certificate Validation in data parser module. A local attacker with higEPSS 0.2%CVE-2025-0309MEDIUMNetskope Client Local Elevation of PrivilegesEPSS 0.2%CVE-2024-5918MEDIUMPAN-OS: Improper Certificate Validation Enables Impersonation of a Legitimate GlobalProtect UserEPSS 0.2%CVE-2026-52688HIGHRRSIGs with too few labels can lead to bypass of DNSSEC wildcard validationEPSS 0.2%CVE-2024-8287HIGHAnbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent.EPSS 0.2%CVE-2026-0233LOWAutonomous Digital Experience Manager: Improper validation of ADEM certificateEPSS 0.2%CVE-2025-65290HIGHAqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HEPSS 0.2%CVE-2025-65291HIGHAqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS conneEPSS 0.2%CVE-2024-31853HIGHA vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS serveEPSS 0.2%CVE-2024-31854HIGHA vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS serveEPSS 0.2%