CWE-295 · 1,502 records
Improper certificate validation
Why does it happen?
A certificate validation error is silently swallowed instead of terminating the connection. Often, code added for a test environment makes its way into production.
Vulnerable and fixed code
A representative teaching example. Highlighted lines mark where the bug and the fix are.
Vulnerable
override fun checkServerTrusted(chain: Array<X509Certificate>, type: String) { // Left empty for the test environment}Fixed
val client = OkHttpClient.Builder() .certificatePinner( CertificatePinner.Builder() .add("api.sirius.example", "sha256/…") .build() ).build()How to prevent it
- 01Don’t modify the platform’s default chain of trust.
- 02Use certificate pinning in critical applications.
- 03Prevent test configurations from reaching production builds.
CVEs in this class
1,504 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
90Now | CVE-2022-26923Weaponized | Active Directory Domain Services Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-295 | High8.8 | KEV | 83.5% | May 10, 2022 |
89Now | CVE-2020-0601Weaponized | A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacmicrosoft · windows 10 1507 · CWE-295 | High8.1 | KEV | 89.4% | Jan 14, 2020 |
71This week | CVE-2026-85102Weaponized | Improper Certificate Validation in Quantum Security Gatewaycheckpoint · gaia embedded · CWE-295 | Critical9.8 | KEV | 7.5% | Sep 9, 2026 |
65This week | CVE-2009-3555Proof of concept | The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in thapache · http server · CWE-295 | Critical9.8 | — | 87.3% | Nov 9, 2009 |
61This week | CVE-2023-20963Weaponized | In WorkSource, there is a possible parcel mismatch.google · android · CWE-295 | High7.8 | KEV | 1.5% | Mar 24, 2023 |
56Plan | CVE-2023-41991Weaponized | A certificate validation issue was addressed.apple · ipados · CWE-295 | Medium5.5 | KEV | 13.4% | Sep 21, 2023 |
42Plan | CVE-2022-42979No exploit | Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows attackers to take ovrydesharing · ryde · CWE-295 | High8.8 | — | 24.3% | Jan 6, 2023 |
42Plan | CVE-2017-2800Proof of concept | A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certifwolfssl · wolfssl · CWE-295 | Critical9.8 | — | 8.5% | May 24, 2017 |
41Plan | CVE-2018-12829No exploit | Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability.adobe · creative cloud · CWE-295 | Critical9.8 | — | 5.1% | Aug 29, 2018 |
40Plan | CVE-2018-4991No exploit | Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validation vulnerability.adobe · creative cloud · CWE-295 | Critical9.8 | — | 4.0% | May 19, 2018 |
40Plan | CVE-2015-2320No exploit | The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.mono-project · mono · CWE-295 | Critical9.8 | — | 3.5% | Jan 8, 2018 |
40Plan | CVE-2020-28907No exploit | Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via venagios · fusion · CWE-295 | Critical9.8 | — | 3.4% | May 24, 2021 |
40Plan | CVE-2018-21029No exploit | systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS.systemd project · systemd · CWE-295 | Critical9.8 | — | 3.1% | Oct 30, 2019 |
40Plan | CVE-2021-33907No exploit | The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .mzoom · meetings · CWE-295 | Critical9.8 | — | 3.0% | Sep 27, 2021 |
40Plan | CVE-2024-49369Proof of concept | Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connectionsicinga · icinga · CWE-295 | Critical9.8 | — | 2.9% | Nov 12, 2024 |
40Plan | CVE-2020-1952No exploit | An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2.apache · iotdb · CWE-295 | Critical9.8 | — | 2.7% | Apr 27, 2020 |
40Plan | CVE-2021-43882No exploit | Microsoft Defender for IoT Remote Code Execution Vulnerabilitymicrosoft · defender for iot · CWE-295 | Critical9.8 | — | 2.4% | Dec 15, 2021 |
40Plan | CVE-2023-26463No exploit | strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes witstrongswan · strongswan · CWE-295 | Critical9.8 | — | 2.3% | Apr 14, 2023 |
40Plan | CVE-2019-18847No exploit | Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.akamai · enterprise application access · CWE-295 | Critical9.8 | — | 2.3% | Aug 26, 2020 |
40Plan | CVE-2019-3777No exploit | Apps Manager unverified SSL certs in Cloud Controller proxypivotal software · application service · CWE-295 | Critical9.8 | — | 1.9% | Mar 7, 2019 |
40Plan | CVE-2016-1000030No exploit | Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutlpidgin · pidgin · CWE-295 | Critical9.8 | — | 1.8% | Sep 5, 2018 |
40Plan | CVE-2015-3886No exploit | libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified impact via unknown libinfinity project · libinfinity · CWE-295 | Critical9.8 | — | 1.7% | Jul 21, 2017 |
40Plan | CVE-2025-68121No exploit | Unexpected session resumption in crypto/tlsgolang · go · CWE-295 | Critical10.0 | — | 0.9% | Feb 5, 2026 |
40Plan | CVE-2024-5261No exploit | TLS certificate are not properly verified when utilizing LibreOfficeKitlibreoffice · libreoffice · CWE-295 | Critical10.0 | — | 0.4% | Jun 25, 2024 |
40Plan | CVE-2026-4370No exploit | Improper TLS Client/Server authentication and certificate verification on Database Clustercanonical · juju · CWE-295 | Critical10.0 | — | 0.4% | Apr 1, 2026 |
- CVE-2022-2692390Now
Active Directory Domain Services Elevation of Privilege Vulnerability
HighCVSS 8.8KEVWeaponizedEPSS 84%microsoft · windows 10 1507May 10, 2022
- CVE-2020-060189Now
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attac
HighCVSS 8.1KEVWeaponizedEPSS 89%microsoft · windows 10 1507Jan 14, 2020
- CVE-2026-8510271This week
Improper Certificate Validation in Quantum Security Gateway
CriticalCVSS 9.8KEVWeaponizedEPSS 8%checkpoint · gaia embeddedSep 9, 2026
- CVE-2009-355565This week
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th
CriticalCVSS 9.8Proof of conceptEPSS 87%apache · http serverNov 9, 2009
- CVE-2023-2096361This week
In WorkSource, there is a possible parcel mismatch.
HighCVSS 7.8KEVWeaponizedEPSS 1%google · androidMar 24, 2023
- CVE-2023-4199156Plan
A certificate validation issue was addressed.
MediumCVSS 5.5KEVWeaponizedEPSS 13%apple · ipadosSep 21, 2023
- CVE-2022-4297942Plan
Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows attackers to take ov
HighCVSS 8.8No exploitEPSS 24%rydesharing · rydeJan 6, 2023
- CVE-2017-280042Plan
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certif
CriticalCVSS 9.8Proof of conceptEPSS 9%wolfssl · wolfsslMay 24, 2017
- CVE-2018-1282941Plan
Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability.
CriticalCVSS 9.8No exploitEPSS 5%adobe · creative cloudAug 29, 2018
- CVE-2018-499140Plan
Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validation vulnerability.
CriticalCVSS 9.8No exploitEPSS 4%adobe · creative cloudMay 19, 2018
- CVE-2015-232040Plan
The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.
CriticalCVSS 9.8No exploitEPSS 4%mono-project · monoJan 8, 2018
- CVE-2020-2890740Plan
Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via ve
CriticalCVSS 9.8No exploitEPSS 3%nagios · fusionMay 24, 2021
- CVE-2018-2102940Plan
systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS.
CriticalCVSS 9.8No exploitEPSS 3%systemd project · systemdOct 30, 2019
- CVE-2021-3390740Plan
The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .m
CriticalCVSS 9.8No exploitEPSS 3%zoom · meetingsSep 27, 2021
- CVE-2024-4936940Plan
Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connections
CriticalCVSS 9.8Proof of conceptEPSS 3%icinga · icingaNov 12, 2024
- CVE-2020-195240Plan
An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2.
CriticalCVSS 9.8No exploitEPSS 3%apache · iotdbApr 27, 2020
- CVE-2021-4388240Plan
Microsoft Defender for IoT Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 2%microsoft · defender for iotDec 15, 2021
- CVE-2023-2646340Plan
strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes wit
CriticalCVSS 9.8No exploitEPSS 2%strongswan · strongswanApr 14, 2023
- CVE-2019-1884740Plan
Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.
CriticalCVSS 9.8No exploitEPSS 2%akamai · enterprise application accessAug 26, 2020
- CVE-2019-377740Plan
Apps Manager unverified SSL certs in Cloud Controller proxy
CriticalCVSS 9.8No exploitEPSS 2%pivotal software · application serviceMar 7, 2019
- CVE-2016-100003040Plan
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutl
CriticalCVSS 9.8No exploitEPSS 2%pidgin · pidginSep 5, 2018
- CVE-2015-388640Plan
libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified impact via unknown
CriticalCVSS 9.8No exploitEPSS 2%libinfinity project · libinfinityJul 21, 2017
- CVE-2025-6812140Plan
Unexpected session resumption in crypto/tls
CriticalCVSS 10.0No exploitEPSS 1%golang · goFeb 5, 2026
- CVE-2024-526140Plan
TLS certificate are not properly verified when utilizing LibreOfficeKit
CriticalCVSS 10.0No exploitEPSS 0%libreoffice · libreofficeJun 25, 2024
- CVE-2026-437040Plan
Improper TLS Client/Server authentication and certificate verification on Database Cluster
CriticalCVSS 10.0No exploitEPSS 0%canonical · jujuApr 1, 2026