Falhas do tipo CWE-327

401 resultados

Uso de algoritmo criptográfico quebrado ou inseguro

A aplicação usa um algoritmo de criptografia que já foi criptanaliticamente quebrado ou é considerado inseguro para o caso de uso. Isso expõe dados sensíveis a decriptação não autorizada, mesmo que o código implemente corretamente a biblioteca criptográfica escolhida.

Exemplo

Um sistema de autenticação usa MD5 ou SHA1 para hash de senhas, ou uma API de pagamento trafega dados com DES ou RC4 em vez de AES. Um atacante consegue recuperar a senha original via força bruta ou quebra criptanalítica em tempo viável.

Como mitigar

Use apenas algoritmos criptográficos modernos e bem mantidos: SHA-256+ para hash, AES-256 para cifra simétrica, RSA-2048+ ou ECDP-256+ para assimétrica. Audite regularmente o stack criptográfico e mantenha dependências atualizadas; remova suporte a algoritmos legados em produção.

CVE-2026-10804LOWStreamlit Palette hashing.py weak hashEPSS 0.1%CVE-2026-11481LOWyoanbernabeu grepai Postgres Embedding Cache chunker.go PostgresStore.LookupByContentHash weak hashEPSS 0.1%CVE-2019-25651CRITICALUbiquiti UniFi Devices Use of AES-CBC Allows Key Recovery and Unauthorized Device ControlEPSS 0.1%CVE-2023-37396LOWIBM Aspera Faspex information disclosureEPSS 0.1%CVE-2025-58743HIGHInsecure Encryption Algorithms Enable Brute-Force Database Credential Access in Milner ImageDirector CaptureEPSS 0.1%CVE-2026-11329LOWonnx onnx-mlir Placeholder Node Cache backend.py generate_hash_key weak hashEPSS 0.1%CVE-2026-21444MEDIUMlibtpms returns wrong initialization vector when certain symmetric ciphers are usedEPSS 0.1%CVE-2025-10237HIGHDuring an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could alEPSS 0.1%CVE-2026-10813LOWLMCache KV Cache utils.py hex_hash_to_int16 weak hashEPSS 0.1%CVE-2026-11330LOWthedotmack claude-mem Observation Content Hash store.ts computeObservationContentHash weak hashEPSS 0.1%CVE-2026-10812LOWzilliztech GPTCache Cache Key pre.py BufferedReader.peek weak hashEPSS 0.1%CVE-2026-10801LOWmodelscope ms-swift PIL Image Cache Key base.py Template._save_pil_image weak hashEPSS 0.1%CVE-2026-10766LOWmlrun DataFrame Hash helpers.py mlrun.utils.helpers.calculate_dataframe_hash weak hashEPSS 0.1%CVE-2026-10800LOWPaddlePaddle FastDeploy MultimodalHasher hasher.py hash_features weak hashEPSS 0.1%CVE-2026-16458MEDIUMTiming side-channel in RSA PKCS#1 v1.5 decryption in ocryptoEPSS 0.1%CVE-2026-16459MEDIUMTiming side-channel in RSA PKCS#1 v1.5 decryption in Oberon PSA CryptoEPSS 0.1%CVE-2025-46371LOWDell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low prEPSS 0.1%CVE-2023-37395LOWIBM Aspera Faspex information disclosureEPSS 0.1%CVE-2026-50268LOWSteeltoe: OAEP setting silently selects PKCS#1 v1.5 paddingEPSS 0.0%CVE-2026-18153MEDIUMIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS