VulnSea

CWE-295

CVEs classified under CWE-295, newest first.

182 CVEsRSS

CVE-2026-50149Medium· 6.5
1mo ago

Contour is a Kubernetes ingress controller using Envoy proxy

Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, when an `HTTPProxy` is configured with incompatible combination of both `.spec.virtualhost.tls.enableFallbackCertificate: true` and `.spec.v…

▾ Sunlitprojectcontour · github.com/projectcontour/contourEPSS 0.18%via NVD
CVE-2026-59825High· 7.4
1mo ago

Mastodon is a free, open-source social network server based on ActivityPub

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-52723Critical· 9.1
1mo ago

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration performs VAU server certificate validation in app/vau/VAUProtoko…

▾ MidnightEPSS 0.38%via NVD
CVE-2026-50578High· 7.5
1mo ago

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration disables TLS certificate verification for both ePA connections i…

▾ TwilightEPSS 0.31%via NVD
CVE-2026-63336Medium
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.ConnectionFactory.useSslProtocol() and ConnectionFactory.useSslProtocol(String) …

▾ Sunlitrabbitmq · com.rabbitmq:amqp-clientEPSS 0.31%via NVD
CVE-2026-66795Critical· 9.9
1mo ago

A flaw was found in the managedcluster-import-controller

A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. …

▾ MidnightRed Hat · multicluster-engine/managedcluster-import-controller-rhel9EPSS 0.49%via NVD
CVE-2026-49457Critical· 9.1
1mo ago

erlang_quic is a pure Erlang QUIC implementation

erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not valida…

▾ Midnightquic · quicEPSS 0.25%via NVD
CVE-2026-0296High· 7.4
1mo ago

Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications

Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is no…

▾ Twilightpaloaltonetworks · globalprotectEPSS 0.14%via NVD
CVE-2026-70454High· 8.0
1mo ago

rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise i…

rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise i…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.25%via NVD
CVE-2026-71290Critical· 9.1
1mo ago

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and mo…

▾ Midnightapache · httpclientEPSS 0.33%via NVD
CVE-2026-15554High· 7.4
1mo ago

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentica…

▾ TwilightRed Hat · io.undertow/undertow-coreEPSS 0.34%via NVD
CVE-2026-66760Medium· 6.4
1mo ago

SAP Approuter does not correctly validate client certificates in certain callback flows

SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, could bypass the identity check…

▾ Sunlitsap · approuterEPSS 0.18%via NVD
CVE-2026-11814Medium· 6.8
1mo ago

A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of …

A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of …

▾ Sunlitnetgear · be9300_firmwareEPSS 0.91%via NVD
CVE-2026-67598High· 7.4PoC
1mo ago

Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitra…

Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitra…

▾ MidnightEPSS 0.26%via NVD
CVE-2026-69248High· 7.4
1mo ago

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 45.0.0 through 48.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate h…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.31%via NVD
CVE-2026-8763High· 7.4
1mo ago

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.…

▾ TwilightRed Hat · Red Hat Ceph Storage 9EPSS 0.45%via NVD
CVE-2026-59638High· 7.4
1mo ago

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc…

▾ TwilightRed HatEPSS 0.34%via NVD
CVE-2026-67294Medium· 5.9
1mo ago

FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication

FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication. In x509_utils_verify(), when server-purpose (X509_PURPOSE_SSL_SERVER) verification fail…

▾ Sunlitfreerdp · freerdpEPSS 0.36%via NVD
CVE-2026-67293Medium· 4.2
1mo ago

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. The TLS hostname matcher (tls_match_hostname() in libfreerdp/crypto/tls.c) treats a wildcard pattern such as *.exampl…

▾ SunlitEPSS 0.23%via NVD
CVE-2026-66402Critical· 9.8
1mo ago

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names()

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Commo…

▾ MidnightEPSS 0.50%via NVD
CVE-2026-8497High· 7.4
2mo ago

Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive informa…

Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive informa…

▾ Twilightdevolutions · password_managerEPSS 0.13%via NVD
CVE-2026-46968Medium· 5.9
2mo ago

Vulnerability in Oracle Java SE (component: JSSE)

Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enter…

▾ Sunlitoracle · jreEPSS 0.29%via NVD
CVE-2026-56820High· 7.4
2mo ago

io.netty/netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack (CVE-2026-56820)

A flaw was found in Netty. The `OcspClient` component fails to validate that the Certificate ID in an Online Certificate Status Protocol (OCSP) response matches the requested Certificate ID. This vulnerability allows a remote attacker to b…

▾ TwilightRed Hat · Red Hat Data Grid 8.6.3EPSS 0.31%via CSAF
CVE-2026-54481High· 7.5
2mo ago

Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override

Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.30%via GHSA
CVE-2026-55001High· 7.8
2mo ago

Active Directory Domain Services Elevation of Privilege Vulnerability

Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.30%via CVEORG
CVE-2026-50302Medium· 4.2
2mo ago

Windows Cryptographic Services Security Feature Bypass Vulnerability

Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.

▾ SunlitMicrosoft · Windows 10 Version 21H2EPSS 0.33%via CVEORG
CVE-2026-47632High· 8.8
2mo ago

Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network.

Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network.

▾ Twilightmicrosoft · azure_connected_machine_agentEPSS 0.50%via NVD
GHSA-8f6j-263m-g72xMedium
2mo ago

Apple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks

Apple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks

▾ Sunlitapp-store-server-library · app-store-server-libraryvia GHSA
CVE-2026-0277Medium· 5.9
2mo ago

An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic

An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android a…

▾ Sunlitpaloaltonetworks · prisma_access_agentEPSS 0.20%via NVD
CVE-2026-59818Medium· 6.5
2mo ago

etcd is a distributed key-value store for the data of a distributed system

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is configured with --listen-client-http-urls to split HTTP and gRPC client endpoints onto separate listeners, the --client-…

▾ Sunlitetcd · etcdEPSS 0.43%via NVD
CWE-295 vulnerabilities (CVEs) — page 4 · VulnSea