← Back
CWE-295

1,445 CVEs • Abstraction: Base

Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

JSON object

Loading...

CVEs (1,445)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Broadcom
CanonicalFedoraproject+2 more
6Balsa
Cloud BackupFabric Operating System+3 more
Jun 17, 2026
May 28, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in...Show more
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications that fail to provide the server identity, including Balsa before 2.5.11 and 2.6.x before 2.6.1, accept a TLS certificate if the certificate is valid for any host.Show less
1Pichi Project
1Pichi
Jun 17, 2026
May 26, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The boost ASIO wrapper in net/asio.cpp in Pichi before 1.3.0 lacks TLS hostname verification.
1Qore
1Qore
Jun 17, 2026
May 26, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
lib/QoreSocket.cpp in Qore before 0.9.4.2 lacks hostname verification for X.509 certificates.
3Axel Project
FedoraprojectOpensuse
4Axel
Backports SleFedora+1 more
Jun 17, 2026
May 26, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.
2Em Http Request Project
Fedoraproject
2Em Http Request
Fedora
Jun 17, 2026
May 25, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
May 21, 2020
N/A· v4
7.5 HIGH· v3
9.3 HIGH· v2
A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC, aka 'Windows Task Scheduler Security Feature Bypass Vulnerability'...Show more
A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC, aka 'Windows Task Scheduler Security Feature Bypass Vulnerability'.Show less
1Em Imap Project
1Em Imap
Jun 17, 2026
May 19, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
em-imap 0.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.
1Redhat
2Keycloak
Openstack
Jun 17, 2026
May 15, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MIT...Show more
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.Show less
2Fedoraproject
Nextcloud
2Fedora
Mail
Jun 17, 2026
May 12, 2020
N/A· v4
7.0 HIGH· v3
6.8 MEDIUM· v2
A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.
1Zephyrproject
1Zephyr
Jun 17, 2026
May 11, 2020
N/A· v4
4.8 MEDIUM· v3
5.8 MEDIUM· v2
The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firmware images requiring valid signatures. However, there is no benefit to using DTLS without the peer...Show more
The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firmware images requiring valid signatures. However, there is no benefit to using DTLS without the peer checking. See NCC-ZEP-018 This issue affects: zephyrproject-rtos zephyr version 2.1.0 and later versions.Show less
1Zulipchat
1Zulip Desktop
Jun 17, 2026
May 9, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled during an attempt to recognize the ignoreCerts option.
1Java Websocket Project
1Java Websocket
Jun 17, 2026
May 7, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.
1Jenkins
1Amazon Ec2
Jun 17, 2026
May 6, 2020
N/A· v4
5.6 MEDIUM· v3
6.8 MEDIUM· v2
Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostname validation, enabling man-in-the-middle attacks.
1Silver Peak
24Nx 1000 Firmware
Nx 10k FirmwareNx 11k Firmware+21 more
Jun 17, 2026
May 5, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted portal.
1Silver Peak
24Nx 1000 Firmware
Nx 10k FirmwareNx 11k Firmware+21 more
Jun 17, 2026
May 5, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator.
1Br Automation
1Automation Studio
Jun 17, 2026
Apr 29, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A missing secure communication definition and an incomplete TLS validation in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.5SP, < 4.6.4 and < 4.7.2 enable unauth...Show more
A missing secure communication definition and an incomplete TLS validation in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.5SP, < 4.6.4 and < 4.7.2 enable unauthenticated users to perform MITM attacks via the B&R upgrade server.Show less
1Apache
1Iotdb
Jun 17, 2026
Apr 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, clients could execute code remotely.
4Apache
DebianOracle+1 more
46Communications Application Session Controller
Communications Billing And Revenue ManagementCommunications Eagle Ftp Table Base Retrieval+43 more
Jun 17, 2026
Apr 27, 2020
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through tha...Show more
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1Show less
1F5
1Nginx Controller
Jun 17, 2026
Apr 23, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS verification by default.
1Mailstore
1Mailstore Server
Jun 17, 2026
Apr 23, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In MailStore Outlook Add-in (and Email Archive Outlook Add-in) through 12.1.2, the login process does not validate the validity of the certificate presented by the server.