Falhas do tipo CWE-295

856 resultados

Validação inadequada de certificado SSL/TLS

A aplicação não valida corretamente o certificado SSL/TLS do servidor remoto, aceitando certificados inválidos, expirados ou emitidos por autoridades não confiáveis. Isso permite que um atacante em posição de intermediário (man-in-the-middle) intercepte a comunicação criptografada e acesse dados sensíveis que deveriam estar protegidos.

Exemplo

Uma aplicação mobile conecta a uma API via HTTPS mas ignora erros de validação de certificado (ou desabilita a verificação para 'facilitar testes'). Um atacante na mesma rede WiFi consegue interceptar requisições, roubar tokens de autenticação ou credenciais do usuário.

Como mitigar

Sempre validar o certificado do servidor (hostname, cadeia de confiança, data de validade). Em desenvolvimento, use certificados válidos mesmo em ambientes de teste; nunca desabilite validação em produção. Considere certificate pinning para APIs críticas, fixando o certificado esperado na aplicação.

CVE-2026-52688HIGHRRSIGs with too few labels can lead to bypass of DNSSEC wildcard validationEPSS 0.1%CVE-2026-44900HIGHepa4all-client: VAU Signature bypassEPSS 0.1%CVE-2025-8393HIGHDreame Technology iOS and Android Mobile Applications Improper Certificate ValidationEPSS 0.1%CVE-2026-2748HIGHS/MIME Certificate Subject WhitespaceEPSS 0.1%CVE-2026-29140HIGHS/MIME Signature Additional CertificateEPSS 0.1%CVE-2024-39771MEDIUMQBiC CLOUD CC-2L v1.1.30 and earlier and Safie One v1.8.2 and earlier do not properly validate certificates, which may allow a network-adjacEPSS 0.1%CVE-2026-44309MEDIUMgitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commitsEPSS 0.1%CVE-2026-18679MEDIUMKong Mesh: kuma-dp connects to the control plane without verifying the TLS certificate when no CA is configuredEPSS 0.1%CVE-2025-65083LOWGoSign Desktop through 2.4.1 disables TLS certificate validation when configured to use a proxy server. This can be problematic if the GoSigEPSS 0.1%CVE-2026-9758HIGHImproper Certificate Validation in S2OPCEPSS 0.1%CVE-2026-79691HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper CertificEPSS 0.1%CVE-2025-2183MEDIUMGlobalProtect App: Improper Certificate Validation Leads to Privilege EscalationEPSS 0.1%CVE-2026-66760MEDIUMMultiple vulnerabilities in SAP Business AI Platform (Approuter)EPSS 0.1%CVE-2025-9785HIGHMisconfigured certificate validation with self-signed certificates for Print DeployEPSS 0.1%CVE-2026-78323MEDIUMJss: jss: jsstrustmanager does not verify nss trust flags on ca certificatesEPSS 0.1%CVE-2026-79642MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper CertificEPSS 0.1%CVE-2026-79732LOWDell Secure Connect Gateway (SCG) 5.0 Appliance, versions prior to 5.36.00.xx, contains an Improper Certificate Validation vulnerability. AnEPSS 0.1%CVE-2026-0249MEDIUMGlobalProtect App: Certificate Validation Bypass VulnerabilitiesEPSS 0.1%CVE-2019-25652HIGHUniFi Network Controller Improper Certificate Validation Leading to Credential Theft via MITMEPSS 0.1%CVE-2026-87571MEDIUMImproper certificate validation in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering toEPSS 0.1%