Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.
URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification
RouterOS provides various services that rely on correct verification of client and server certificates to secure confide
Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacke
The OpenTelemetry.Exporter.Instana exports telemetry to Instana backend. Prior to 1.1.0, the OpenTelemetry.Exporter.Inst
Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote un
Partial-chain certificate verification may accept chains that terminate at a peer-supplied, untrusted intermediate certi
etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is con
A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certif
DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activi
Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, when an `HTTPProxy` is
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing
A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validat
Netmaker disables certificate verification on the connection to the configured mail server. The sender in pro/email/smtp
SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges
When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were
rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an
An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 micr
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a pri
When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the curl tool,curl should check the pu
Amazon SageMaker Python SDK before v3.1.1 or v2.256.0 disables TLS certificate verification for HTTPS connections made b
The DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Althou
The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. F
Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the
Botan is a C++ cryptography library. Prior to version 3.11.0, during processing of an X.509 certificate path using name
The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostna
Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certif
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, on GnuTLS builds,
A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the s
An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attack
Open ISES Tickets before 3.44.2 disables TLS certificate verification in ajax/reports.php by setting CURLOPT_SSL_VERIFYP
Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/functions.inc.php by setting CURLOPT_SSL_V
Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/login.inc.php by setting CURLOPT_SSL_VERIF
Open ISES Tickets before 3.44.2 disables TLS certificate verification in rm/incs/mobile_login.inc.php by setting CURLOPT
Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections wi
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1
An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a ma
IBM TS4500 CLI tool Versions: 0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validat
FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-si
X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in anylabeling/services/auto
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthe
IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate valid
IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle te
css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allo
The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potential
A third-party NAT traversal module fails to validate SSL/TLS certificates when connecting to the signaling server. While
Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a cert
Frequently Asked Questions
What is CWE-295?
CWE-295 (CWE-295) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-295?
There are 1,771 CVE records associated with CWE-295 in our database. Of these, 124 are critical severity, 576 are high severity, and 675 are medium severity.
How can I protect against CWE-295 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-295 using AI-powered security agents.
Detect CWE-295 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-295 vulnerabilities across your infrastructure.
Get Started