Skip to content
Noroxi

CWE-295 · 1,502 records

Improper certificate validation

Why does it happen?

A certificate validation error is silently swallowed instead of terminating the connection. Often, code added for a test environment makes its way into production.

Vulnerable and fixed code

A representative teaching example. Highlighted lines mark where the bug and the fix are.

Vulnerable

kotlin
override fun checkServerTrusted(chain: Array<X509Certificate>, type: String) {  // Left empty for the test environment}

Fixed

kotlin
val client = OkHttpClient.Builder()  .certificatePinner(    CertificatePinner.Builder()      .add("api.sirius.example", "sha256/…")      .build()  ).build()

How to prevent it

  1. 01Don’t modify the platform’s default chain of trust.
  2. 02Use certificate pinning in critical applications.
  3. 03Prevent test configurations from reaching production builds.

CVEs in this class

1,504 records

  • Active Directory Domain Services Elevation of Privilege Vulnerability

    HighCVSS 8.8KEVWeaponizedEPSS 84%

    microsoft · windows 10 1507May 10, 2022

  • A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attac

    HighCVSS 8.1KEVWeaponizedEPSS 89%

    microsoft · windows 10 1507Jan 14, 2020

  • CVE-2026-85102
    71This week

    Improper Certificate Validation in Quantum Security Gateway

    CriticalCVSS 9.8KEVWeaponizedEPSS 8%

    checkpoint · gaia embeddedSep 9, 2026

  • CVE-2009-3555
    65This week

    The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th

    CriticalCVSS 9.8Proof of conceptEPSS 87%

    apache · http serverNov 9, 2009

  • CVE-2023-20963
    61This week

    In WorkSource, there is a possible parcel mismatch.

    HighCVSS 7.8KEVWeaponizedEPSS 1%

    google · androidMar 24, 2023

  • A certificate validation issue was addressed.

    MediumCVSS 5.5KEVWeaponizedEPSS 13%

    apple · ipadosSep 21, 2023

  • Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows attackers to take ov

    HighCVSS 8.8No exploitEPSS 24%

    rydesharing · rydeJan 6, 2023

  • A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certif

    CriticalCVSS 9.8Proof of conceptEPSS 9%

    wolfssl · wolfsslMay 24, 2017

  • Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability.

    CriticalCVSS 9.8No exploitEPSS 5%

    adobe · creative cloudAug 29, 2018

  • Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validation vulnerability.

    CriticalCVSS 9.8No exploitEPSS 4%

    adobe · creative cloudMay 19, 2018

  • The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.

    CriticalCVSS 9.8No exploitEPSS 4%

    mono-project · monoJan 8, 2018

  • Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via ve

    CriticalCVSS 9.8No exploitEPSS 3%

    nagios · fusionMay 24, 2021

  • systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS.

    CriticalCVSS 9.8No exploitEPSS 3%

    systemd project · systemdOct 30, 2019

  • The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .m

    CriticalCVSS 9.8No exploitEPSS 3%

    zoom · meetingsSep 27, 2021

  • Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connections

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    icinga · icingaNov 12, 2024

  • An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2.

    CriticalCVSS 9.8No exploitEPSS 3%

    apache · iotdbApr 27, 2020

  • Microsoft Defender for IoT Remote Code Execution Vulnerability

    CriticalCVSS 9.8No exploitEPSS 2%

    microsoft · defender for iotDec 15, 2021

  • strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes wit

    CriticalCVSS 9.8No exploitEPSS 2%

    strongswan · strongswanApr 14, 2023

  • Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.

    CriticalCVSS 9.8No exploitEPSS 2%

    akamai · enterprise application accessAug 26, 2020

  • Apps Manager unverified SSL certs in Cloud Controller proxy

    CriticalCVSS 9.8No exploitEPSS 2%

    pivotal software · application serviceMar 7, 2019

  • Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutl

    CriticalCVSS 9.8No exploitEPSS 2%

    pidgin · pidginSep 5, 2018

  • libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified impact via unknown

    CriticalCVSS 9.8No exploitEPSS 2%

    libinfinity project · libinfinityJul 21, 2017

  • Unexpected session resumption in crypto/tls

    CriticalCVSS 10.0No exploitEPSS 1%

    golang · goFeb 5, 2026

  • TLS certificate are not properly verified when utilizing LibreOfficeKit

    CriticalCVSS 10.0No exploitEPSS 0%

    libreoffice · libreofficeJun 25, 2024

  • Improper TLS Client/Server authentication and certificate verification on Database Cluster

    CriticalCVSS 10.0No exploitEPSS 0%

    canonical · jujuApr 1, 2026

All vulnerability classes