Weaknesses of type CWE-327

401 results

Uso de algoritmo criptográfico fraco ou quebrado

A aplicação usa algoritmos de criptografia que já foram quebrados ou são reconhecidamente fracos (como MD5, SHA-1, DES, RC4), deixando dados sensíveis vulneráveis a ataques práticos. Mesmo que o algoritmo ainda funcione tecnicamente, um adversário pode recuperar a mensagem ou falsificar assinaturas com esforço computacional viável.

Example

Um sistema armazena senhas de usuários com hash MD5, ou usa SHA-1 para assinar tokens JWT, ou criptografa dados financeiros com DES. Em todos esses casos, há ferramentas públicas que conseguem quebrar a proteção em horas ou dias.

How to mitigate

Substitua por algoritmos modernos: SHA-256 ou melhor para hash (ou Argon2/bcrypt para senhas), AES-256 para criptografia simétrica, ECDSA ou RSA-2048+ para assinaturas. Revise periodicamente o acervo de dependências e remova bibliotecas que só ofereçam primitivas fracas.

CVE-2026-26219CRITICALnewbee-mall Unsalted MD5 Password Hashing Enables Offline Credential CrackingEPSS 0.2%CVE-2026-54147MEDIUMhttp4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URIEPSS 0.2%CVE-2024-31896MEDIUMIBM SPSS Statistics information disclosureEPSS 0.2%CVE-2024-45671MEDIUMIBM Security Verify Information Queue information disclosureEPSS 0.2%CVE-2024-26317MEDIUMIn illumos illumos-gate 2024-02-15, an error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinatEPSS 0.2%CVE-2026-5682MEDIUMMeesho Online Shopping App com.meesho.supply endpoint risky encryptionEPSS 0.2%CVE-2026-7103MEDIUMcode-projects Chat System MD5 Hash update_user.php weak hashEPSS 0.2%CVE-2025-49756LOWOffice Developer Platform Security Feature Bypass VulnerabilityEPSS 0.2%CVE-2026-27519HIGHBinardat 10G08-0800GSM Network Switch Hard-coded RC4 Encryption KeyEPSS 0.2%CVE-2025-27458MEDIUMCVE-2025-27458EPSS 0.2%CVE-2026-66407HIGHDEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrievEPSS 0.2%CVE-2026-9261HIGHUse of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlierEPSS 0.2%CVE-2025-43723MEDIUMDell PowerScale OneFS, versions prior to 9.10.1.3 and versions 9.11.0.0 through 9.12.0.0, contains a use of a broken or risky cryptographic EPSS 0.2%CVE-2026-8803MEDIUMopensourcepos Open Source Point of Sale Employee Login Employee.php login weak hashEPSS 0.2%CVE-2025-2545LOWDeprecated 3DES cryptographic algorithm used by Request Tracker in emails encrypted with S/MIMEEPSS 0.2%CVE-2026-5926MEDIUMSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.2%CVE-2024-5559MEDIUMCWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attaEPSS 0.2%CVE-2026-28479HIGHOpenClaw < 2026.2.15 - Cache Poisoning via Deprecated SHA-1 Hash in Sandbox ConfigurationEPSS 0.2%CVE-2026-81438LOWDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. AEPSS 0.2%CVE-2026-27871LOWTL280EPSS 0.2%