Threats Tagged 'cwe-295'
View all threats tagged with 'cwe-295'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-295'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-64993: CWE-295: Improper Certificate Validation in Dell RVToolsCVE-2026-64993 0 Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity. Join the discussion | CVE Database V5 | 08/06/2026, 13:38:42 UTC Added: 08/06/2026, 13:56:59 UTC |
CVE-2026-16792: CWE-295 Improper certificate validation in Lenovo XClarity OrchestratorCVE-2026-16792 0 An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate validation under certain circumstances. Join the discussion | CVE Database V5 | 08/04/2026, 19:48:03 UTC Added: 08/04/2026, 20:12:01 UTC |
CVE-2026-69248: CWE-295: Improper Certificate Validation in pyca cryptographyCVE-2026-69248 0 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com. This allows acceptance of an invalid certificate chain. This issue is fixed in 49.0.0. Join the discussion | CVE Database V5 | 08/03/2026, 21:21:43 UTC Added: 08/03/2026, 21:48:52 UTC |
In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. (CVE-2026-8763)CVE-2026-8763 0 A critical vulnerability exists in Bouncy Castle for Java before version 1.85 that allows bypassing Name Constraints via a trailing dot in rfc822Name and URI fields. This issue also affects Bouncy Castle for Java LTS versions before 2.73.12 and Bouncy Castle for Java FIPS versions before 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series), and 2.1.3 (2.1.X series). The vulnerability is identified as CVE-2026-8763 and relates to improper validation of name constraints, classified under CWE-295. No patch links are provided, and no known exploits are reported in the wild. Join the discussion | GCVE Database | 08/03/2026, 03:31:56 UTC Added: 08/03/2026, 21:22:08 UTC |
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. (CVE-2026-58062)CVE-2026-58062 0 Bouncy Castle for Java versions before 1.85 improperly accept stapled OCSP responses without verifying that the response is bound to the certificate being checked. This vulnerability also affects Bouncy Castle for Java LTS versions before 2.73.12, and Bouncy Castle for Java FIPS versions before 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series). Join the discussion | GCVE Database | 08/03/2026, 03:31:57 UTC Added: 08/03/2026, 21:22:08 UTC |
CVE-2025-9291: CWE-295 Improper certificate validation in TP-Link Systems Inc. Omada GatewaysCVE-2025-9291 0 A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be bypassed under specific conditions. Successful exploitation may allow interception or modification of communication between affected devices and cloud controllers. Join the discussion | CVE Database V5 | 08/03/2026, 17:48:14 UTC Added: 08/03/2026, 19:03:37 UTC |
CVE-2026-18089: CWE-347 Improper Verification of Cryptographic Signature in TIMLEGGE Net::SAML2CVE-2026-18089 0 Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured. verify_xml in Net::SAML2::Role::VerifyXML runs "return if !$anchors && !$cacert;" as soon as the XML::Sig check succeeds, and that check uses the X.509 certificate taken from the response's own dsig:KeyInfo/dsig:X509Certificate element, so an unanchored response is checked only against the key it carries. Binding::POST declares cacert as an optional Maybe[Str] with no default, so a POST binding built without one takes that path, and _verify_encrypted_assertion returns early the same way with "return $xml unless $cacert;". Any caller that constructs Binding::POST or calls Assertion->new_from_xml without a cacert, cert_text, or anchors argument accepts a response signed by an attacker generated key whose self-signed certificate is embedded in that response, authenticating an arbitrary assertion. Join the discussion | CVE Database V5 | 08/03/2026, 12:42:08 UTC Added: 08/03/2026, 13:33:36 UTC |
CVE-2026-0392: CWE-494 Download of code without integrity check in Latvijas Valsts radio un televīzijas centrs (LVRTC) eParakstītājs 3.0CVE-2026-0392 1 eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is not authenticated or integrity-protected. On each launch the application fetches an update descriptor (XML) over TLS but accepts any TLS certificate (a permissive TrustManager and a HostnameVerifier that always returns true), does not verify any digital signature on the update descriptor, and does not verify the Authenticode signature or a checksum of the downloaded installer before running it. A man-in-the-middle attacker able to redirect www.eparaksts.lv can serve a crafted update descriptor pointing to an attacker-controlled executable, which the client downloads and executes, resulting in arbitrary code execution on the victim host. Join the discussion | CVE Database V5 | 08/03/2026, 09:56:31 UTC Added: 08/03/2026, 10:18:39 UTC |
CVE-2026-18141: Improper Certificate Validation in Red Hat Red Hat Ansible Automation Platform 2.6 for RHEL 9CVE-2026-18141 0 A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The system also inadvertently discloses the expected certificate subject in error messages, which simplifies the attack. This vulnerability allows an attacker to inject arbitrary events into EDA, potentially triggering automated workflows. Join the discussion | CVE Database V5 | 07/31/2026, 15:34:16 UTC Added: 07/31/2026, 19:28:11 UTC |
CVE-2026-18257: CWE-295: Improper Certificate Validation in Systerel S2OPCCVE-2026-18257 0 Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a certificate issued by this root issuer to be considered trusted Join the discussion | CVE Database V5 | 07/29/2026, 16:34:09 UTC Added: 07/29/2026, 18:37:44 UTC |
Showing 1 to 10 of 25 results