MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to
When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during
An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio
An issue pertaining to CWE-295: Improper Certificate Validation was discovered in jxcore jxm master. The application dis
An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application dis
Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, a
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version
Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-respo
A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when p
Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthen
"Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle at
CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5
FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_w
An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not pe
A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacke
In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client
Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or s
Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and pr
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final throug
Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0
Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that all
the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authenti
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12,
In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffic between Splunk SOA
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or a
ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which may allow an attacker
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift:
Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulner
Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side an
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,
An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user ca
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certifi
A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 throu
Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Prior to version 0.13.0, code for client certificate verifi
Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API
Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled (LDAP_USE_TLS = True), Lemur's LDAP aut
Dell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A rem
Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remo
An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local n
The Infotainment ECU manufactured by Bosch which is installed in Nissan Leaf ZE1 – 2020 uses a Redbend service for over-
An issue pertaining to CWE-295: Improper Certificate Validation was discovered in fofolee uTools-quickcommand 5.0.3.
The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP ser
The server certificate was not verified when an Arc agent connected to a Guardian or CMC. A malicious actor could per
Taipower APP for Andorid developed by Taipower has an Improper Certificate Validation vulnerability. When establishing a
A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encrypt
Frequently Asked Questions
What is CWE-295?
CWE-295 (CWE-295) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-295?
There are 1,771 CVE records associated with CWE-295 in our database. Of these, 124 are critical severity, 576 are high severity, and 675 are medium severity.
How can I protect against CWE-295 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-295 using AI-powered security agents.
Detect CWE-295 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-295 vulnerabilities across your infrastructure.
Get Started