CWE-637Class

Unnecessary Complexity in Protection Mechanism (Not Using 'Economy of Mechanism')

Draft in the CWE catalog · 1 CVE mapped

1
CVEs mapped
9.3
Median CVSS
What it is

The product uses a more complex mechanism than necessary, which could lead to resultant weaknesses when the mechanism is not correctly understood, modeled, configured, implemented, or used.

Recent examples
9.3cvss
CVE-2026-9058

Improper Certificate Verification in Szafir SDK

For untrusted certificates that contain the "Authority Information Access - caIssuers URI" extension, Szafir SDK will automatically download the parent CA certificate from the specified URL and will import it to its trust store as a "nonqualified" certificate. In such a case, Szafir SDK returns a success status code of 0 ("Positively verified") upon successful cryptographic verification and a certificate status of "nonqualified". For other types of untrusted certificates, Szafir SDK returns a success status code of 0 ("Positively verified") upon successful cryptographic verification and a certificate status of "nondetermined". This may lead integrating applications to incorrectly treat the digital signature as valid despite an untrusted certificate chain. This flaw enables authentication bypass and user impersonation: (1) in use-cases other than qualified certificate authentication, or (2) if the qualified certificate authentication use-case is not correctly implemented by the integrating application. This issue was fixed in version 1.8.463.2.

CRITICALno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-637
Abstraction
Class
Structure
Simple
Status
Draft
References (2)