CWE-295Base

Improper Certificate Validation

Draft in the CWE catalog · 650 CVEs mapped

650
CVEs mapped
7.1
Median CVSS
What it is

The product does not validate, or incorrectly validates, a certificate.

Recent examples
8.0cvss
CVE-2026-86185

CVE-2026-86185 - HIGH Severity Vulnerability

Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inject arbitrary JavaScript executed in the renderer with access to the privileged IPC bridge, and execute system commands or steal login credentials.

HIGHno explanation yet
epss
7.4cvss
CVE-2026-84961

CVE-2026-84961 - HIGH Severity Vulnerability

undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2.

HIGHno explanation yet
0%
epss
7.4cvss
CVE-2026-85525

CVE-2026-85525 - HIGH Severity Vulnerability

Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and definitive verification failures were treated as transient. A man-in-the-middle attacker holding a revoked certificate and its private key for a Snowflake or stage hostname could cause the driver to establish a TLS session to the attacker-controlled endpoint anyway, allowing the attacker to read and modify data transmitted within that connection. Successful exploitation requires that on-path position and the corresponding private key, and impact is limited to data carried within the intercepted connection. The fix is available in the patched versions listed above. Users must manually upgrade.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-295
Abstraction
Base
Structure
Simple
Status
Draft
References (2)