Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Val
Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authoriza
CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security
dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-contr
When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option
Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capa
SEPPmail Secure Email Gateway before version 15.0.1 improperly validates S/MIME certificates issued for email addresses
An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user ca
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be u
A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a
When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify t
Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsi
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be c
Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Mana
Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildca
Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to ha
A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allow
OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose se
Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v4.10.16-lts,
When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verificat
When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification w
Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to
Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fing
Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k
Improper Certificate Validation vulnerability in Apache Airflow Provider for Databricks. Provider code did not validate
Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter Versions Affected
Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can p
Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OV
aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (
Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows
Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostna
Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the n
DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle at
Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or alt
A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability
A vulnerability was discovered on Stormshield Network Security 4.3.0 to 4.3.41 (included), 4.4.0 to 4.8.15 (included) ,
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.1
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthentica
Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security f
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability.
Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also c
Multiple MFPs provided by Brother Industries, Ltd. does not properly validate server certificates, which may allow a man
The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an externa
Tanium addressed an improper certificate validation vulnerability in Tanium Appliance.
Cosign provides code signing and transparency for containers and binaries. In versions 3.0.4 and below, an issuing certi
The GL-iNet Comet (GL-RM1) KVM connects to a GL-iNet site during boot-up to provision client and CA certificates. The GL
A vulnerability was found in HybridAuth up to 3.12.2. This issue affects some unknown processing of the file src/HttpCli
Frequently Asked Questions
What is CWE-295?
CWE-295 (CWE-295) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-295?
There are 1,771 CVE records associated with CWE-295 in our database. Of these, 124 are critical severity, 576 are high severity, and 675 are medium severity.
How can I protect against CWE-295 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-295 using AI-powered security agents.
Detect CWE-295 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-295 vulnerabilities across your infrastructure.
Get Started