VulnSea

CWE-295

CVEs classified under CWE-295, newest first.

182 CVEsRSS

CVE-2026-55436High· 7.4
2mo ago

Coder's AI Bridge Proxy skips TLS certificate verification in default configuration

Coder's AI Bridge Proxy skips TLS certificate verification in default configuration

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.26%via GHSA
CVE-2026-9545High· 7.5PoC
2mo ago

In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. When libc…

In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. When libc…

▾ Midnighthaxx · curlEPSS 0.41%via NVD
CVE-2026-8286High· 8.1PoC
2mo ago

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

▾ Midnighthaxx · curlEPSS 0.52%via NVD
CVE-2026-12064High· 7.5PoC
2mo ago

When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl

When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initi…

▾ Midnighthaxx · curlEPSS 0.40%via NVD
CVE-2026-11564Critical· 9.1PoC
2mo ago

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store af…

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store af…

▾ Abyssalhaxx · curlEPSS 0.43%via NVD
CVE-2026-47077High
3mo ago

Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM

Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM

▾ Twilighthackney · hackneyEPSS 0.70%via GHSA
CVE-2026-48934Medium· 4.3
3mo ago

A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

▾ SunlitEPSS 0.29%via NVD
CVE-2026-47074High
3mo ago

Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM

Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM

▾ Twilighthackney · hackneyEPSS 0.38%via GHSA
GHSA-8jgf-23q5-x7xxHigh
3mo ago

ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass

ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass

▾ Twilightex_aws_sns · ex_aws_snsvia GHSA
CVE-2026-57289Medium· 4.8
3mo ago

Jenkins Bitbucket Push and Pull Request Plugin unconditionally disables SSL/TLS certificate validation

Jenkins Bitbucket Push and Pull Request Plugin unconditionally disables SSL/TLS certificate validation

▾ Sunlitjenkins · io.jenkins.plugins:bitbucket-push-and-pull-requestEPSS 0.16%via GHSA
CVE-2026-54100High· 8.3
3mo ago

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker …

▾ Twilightredhat · openshift_container_platformEPSS 0.30%via NVD
CVE-2026-9697High· 7.4
3mo ago

undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)

A flaw was found in undici. When undici's ProxyAgent is configured with a SOCKS5 proxy Uniform Resource Identifier (URI), it silently ignores Transport Layer Security (TLS) options, such as custom Certificate Authorities (CAs). This allows…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.55%via CSAF
GHSA-r7g4-qg5f-qqm2Medium· 6.5
3mo ago

Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception

Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception

▾ Sunlitnodemailer · nodemailervia GHSA
CVE-2026-40992Medium· 5.0
3mo ago

Spring Boot's Mail auto-configuration does not enable hostname verification

Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mail.properties.mail.smtp.ssl.checkserveridentity=true, are not affected. Affected version…

▾ Sunlitvmware · spring_bootEPSS 0.18%via NVD
CVE-2026-41714Medium· 4.0
3mo ago

Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification. Affected vers…

Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification. Affected vers…

▾ Sunlitvmware · spring_advanced_message_queuing_protocolEPSS 0.17%via NVD
CVE-2026-42790High· 8.1
4mo ago

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification. Two flaws combine to allow a s…

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification. Two flaws combine to allow a s…

▾ Twilighterlang · erlang/otpEPSS 0.47%via NVD
CVE-2026-42789Medium· 4.8⚖ disputed
4mo ago

Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be accepted as an intermediate issuer, enabling certificate chain forgery. In lib/public_key…

Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be accepted as an intermediate issuer, enabling certificate chain forgery. In lib/public_key…

▾ Sunliterlang · erlang/otpEPSS 0.35%via NVD
CVE-2026-42013High· 8.2
4mo ago

A flaw was found in gnutls

A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker …

▾ TwilightEPSS 0.56%via NVD
CVE-2026-42012High· 7.1
4mo ago

A flaw was found in gnutls

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could ca…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-39828Medium· 6.3⚖ disputed
4mo ago

Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh

When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succee…

▾ Sunlitgolang.org/x/crypto · golang.org/x/crypto/sshEPSS 0.54%via CVEORG
CVE-2026-39835Medium· 5.3
4mo ago

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these…

▾ Sunlitgolang · cryptoEPSS 0.66%via NVD
CVE-2026-42508Critical· 9.1
4mo ago

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

▾ Midnightgolang · cryptoEPSS 0.65%via NVD
CVE-2026-4873Medium· 5.9
4mo ago

A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool

A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to …

▾ Sunlithaxx · curlEPSS 0.36%via NVD
CVE-2026-8367Medium· 4.8
4mo ago

aria2c accepts a server certificate with incorrect Extended Key Usage (EKU)

aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authenti…

▾ Sunlitaria2_project · aria2EPSS 0.19%via NVD
CVE-2026-42011High· 7.4
4mo ago

A flaw was found in gnutls

A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to byp…

▾ TwilightEPSS 0.57%via NVD
CVE-2026-43869High· 7.3
4mo ago

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

▾ Twilightapache · thriftEPSS 0.81%via NVD
CVE-2026-41603High· 7.4
5mo ago

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

▾ Twilightapache · thriftEPSS 0.57%via NVD
CVE-2025-40745Low· 3.7
5mo ago

A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Simcenter STAR-CCM+ (All versions < V2602), Solid Edge SE202…

A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Simcenter STAR-CCM+ (All versions < V2602), Solid Edge SE202…

▾ SunlitEPSS 0.14%via NVD
CVE-2026-0233High· 8.8
5mo ago

A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges.

A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges.

▾ Twilightpaloaltonetworks · autonomous_digital_experience_managerEPSS 0.18%via NVD
CVE-2026-5263Medium· 6.5
5mo ago

URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c

URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A compromised or malicious sub-CA could issue leaf certificates with URI SAN entries that vio…

▾ Sunlitwolfssl · wolfsslEPSS 0.25%via NVD
CWE-295 vulnerabilities (CVEs) — page 5 · VulnSea