Threats Tagged 'cwe-347'
View all threats tagged with 'cwe-347'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-347'
Click on any threat for detailed analysis and mitigation recommendations
A flaw was found in Red Hat Quay's Stripe billing webhook handler. (CVE-2026-74244)CVE-2026-74244 0 A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signature header. Successful exploitation can lead to the unauthorized resetting of a namespace's build quota to its maximum and trigger unsolicited billing emails to namespace administrators. Join the discussion | GCVE Database | 08/15/2026, 00:31:24 UTC Added: 08/15/2026, 05:15:18 UTC |
CVE-2026-19910: CWE-347: Improper Verification of Cryptographic Signature in PAX Technology Q80CVE-2026-19910 0 PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The specific flaw exists within the application installer. The issue results from the lack of proper verification of a cryptographic signature before installing an application. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-30585. Join the discussion | CVE Database V5 | 08/14/2026, 21:31:35 UTC Added: 08/14/2026, 20:11:47 UTC |
CVE-2026-47192: CWE-347: Improper Verification of Cryptographic Signature in siemens kasCVE-2026-47192 0 kas is a setup tool for bitbake based projects. Starting in version 4.8 and prior to version 5.3, kas checks out and processes repositories regarding configuration includes prior to validating signatures of those repositories. This may allow to replace on original repository with one under the control of an attacker under very specific conditions. First of all, the attacker must have gained control of a repository that a kas file of the victim is referencing. Furthermore, the following conditions must be fulfilled: the victim's kas configuration must include a configuration file from the attacked repository; the repository state is referenced by tag, and no commit ID is specified (this is triggering a warning, though); the key used for validating the tag or commit signature is stored as file in a repository; no fingerprint for the key is specified; and the `_source_dir` key must not be set by the victim when calling kas (e.g. by avoiding a local `.config.yaml`). Given these conditions, the attacker could modify the included kas configuration in way that the key used to validate the tag signature of the attacker's repository could be replaced by an attacker-chosen key. No other exploit possibilities have been identified so far, but this does not rule out that those may exist. All patches have been released along with kas version 5.3. As a workaround, pin the expected signature key via its fingerprint, also when storing it as file in a repository. Join the discussion | CVE Database V5 | 08/14/2026, 16:41:27 UTC Added: 08/14/2026, 17:13:51 UTC |
CVE-2026-47191: CWE-347: Improper Verification of Cryptographic Signature in siemens kasCVE-2026-47191 0 kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git commit ID (SHA-1 or SHA-256) to qualify if a checkout of a repository is equivalent to the state validated while adding its commit ID to a kas configuration, users may be tricked to check out a branch of the same name from this repository. This implies that the referenced repository has been taken over by an attacker and modified to carry such a branch. SHA-1 commits may also be replaced by creating hash collisions, so the primary impact of this issue is on SHA-256 commit IDs. Version 5.3 fixes the issue. As a workaround, avoid relying solely on the commit ID for integrity validation of a repository that might become under control of a malicious 3rd party. If available, additional validate cryptographically signed commits or tags. Alternatively, mirror the repository to a save place, validate its integrity, and use this instead of the original one. Join the discussion | CVE Database V5 | 08/14/2026, 16:35:48 UTC Added: 08/14/2026, 16:42:36 UTC |
CVE-2026-56865: CWE-347: Improper Verification of Cryptographic Signature in Go toolchain cmd/goCVE-2026-56865 0 A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. This attack allows for a malicious GOPROXY to serve malicious module content that cannot be detected by evaluating the transparency log. All tiles are now correctly verified against their parents. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ && go mod tidy Join the discussion | CVE Database V5 | 08/13/2026, 21:58:53 UTC Added: 08/13/2026, 22:11:58 UTC |
CVE-2026-56864: CWE-347: Improper Verification of Cryptographic Signature in Go toolchain cmd/goCVE-2026-56864 0 A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ && go mod tidy Join the discussion | CVE Database V5 | 08/13/2026, 21:58:53 UTC Added: 08/13/2026, 22:11:58 UTC |
CVE-2026-28148: CWE-347 Improper Verification of Cryptographic Signature in miniOrange Headless Single Sign OnCVE-2026-28148 0 Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions. Join the discussion | CVE Database V5 | 08/13/2026, 13:36:26 UTC Added: 08/13/2026, 13:57:08 UTC |
CVE-2026-12263: CWE-347 Improper verification of cryptographic signature in Zohocorp ManageEngine Password Manager ProCVE-2026-12263 0 Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation. Join the discussion | CVE Database V5 | 08/13/2026, 10:18:35 UTC Added: 08/13/2026, 10:42:09 UTC |
CVE-2026-68757: CWE-347 Improper Verification of Cryptographic Signature in jfrog artifactoryCVE-2026-68757 0 A user with access to a valid SAML response may impersonate another user under specific conditions. Join the discussion | GCVE Database | 08/12/2026, 15:10:23 UTC Added: 08/12/2026, 16:11:06 UTC |
CVE-2026-68759: CWE-347 Improper Verification of Cryptographic Signature in jfrog artifactoryCVE-2026-68759 0 A holder of a valid integration credential may impersonate other users under specific conditions. Join the discussion | CVE Database V5 | 08/12/2026, 15:15:50 UTC Added: 08/12/2026, 15:42:06 UTC |
Showing 1 to 10 of 39 results