Falhas do tipo CWE-345

548 resultados

Verificação insuficiente de autenticidade de dados

A aplicação recebe dados de fontes externas (rede, arquivo, entrada do usuário) mas não valida adequadamente se eles realmente vieram de quem diz vir ou se não foram alterados no caminho. Isso permite que um atacante forje, intercepte ou modifique dados sem que o sistema detecte, comprometendo integridade e confiança.

Exemplo

Um serviço REST que confia cegamente em um campo 'user_id' vindo do cliente, sem verificar assinatura ou token, permitindo que alguém mude a URL para acessar dados de outro usuário. Ou um arquivo de configuração lido sem validar sua hash, permitindo execução de código malicioso se o arquivo for corrompido.

Como mitigar

Use mecanismos criptográficos de autenticação (HMAC, assinatura digital, certificados TLS) para garantir a origem e integridade dos dados. No lado do servidor, nunca confie em identificadores ou claims do cliente — valide contra seu próprio estado autorizado (sessão, JWT assinado, etc).

CVE-2026-59247HIGHInsufficient verification of Hex package metadata in GleamEPSS 0.1%CVE-2026-32294HIGHJetKVM insufficient firmware verificationEPSS 0.1%CVE-2026-69105HIGHPotential package cache integrity issue in JFrog ArtifactoryEPSS 0.1%CVE-2026-77955MEDIUMPossible ZONEMD verification bypass windowEPSS 0.1%CVE-2026-54266HIGHAngular: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State PoisoningEPSS 0.1%CVE-2026-34778MEDIUMElectron: Service worker can spoof executeJavaScript IPC repliesEPSS 0.1%CVE-2026-40109LOWFlux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggeringEPSS 0.1%CVE-2025-52638MEDIUMMultiple security vulnerabilities affect HCL AIONEPSS 0.1%CVE-2026-74882HIGHopenssl_encrypt before 1.4.0 Insecure Default ConfigurationEPSS 0.1%CVE-2026-10724MEDIUMReviews Feed < 2.6.5 - Unauthenticated Stored Arbitrary Shortcode Execution via Google ReviewsEPSS 0.1%CVE-2026-39411MEDIUMLobeHub has an unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` headerEPSS 0.1%CVE-2025-7884MEDIUMEluktronics Control Center REG File data authenticityEPSS 0.1%CVE-2026-15150MEDIUMmyCred < 3.2.5 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification in buyCREDEPSS 0.1%CVE-2026-12901MEDIUMGetPaid < 2.8.55 - Unauthenticated Worldpay Payment Bypass via Insufficient IPN VerificationEPSS 0.1%CVE-2023-43636HIGHRootfs Not ProtectedEPSS 0.1%CVE-2026-15152MEDIUMWP Hotel Booking < 2.3.2 - Unauthenticated PayPal Payment BypassEPSS 0.1%CVE-2026-15208MEDIUMRegistrationMagic < 6.0.9.5 - Unauthenticated Payment Bypass via Amount-Blind PayPal VerificationEPSS 0.1%CVE-2023-20576HIGHInsufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of serEPSS 0.1%CVE-2026-16650MEDIUMCharitable < 1.8.12 - Unauthenticated Donation Payment-Status Manipulation via Square Webhook Signature BypassEPSS 0.1%CVE-2026-15147MEDIUMFive Star Restaurant Reservations < 2.7.23 - Unauthenticated Payment Bypass and Booking Confirmation via IDOREPSS 0.1%