CWE-296
CVEs classified under CWE-296, newest first.
2 CVEsRSS
GHSA-6hxq-p678-4hr2LowSimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor
SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor
▾ Sunlitsimplewebauthn · @simplewebauthn/servervia GHSA
CVE-2026-42789Medium· 4.8⚖ disputedImproper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be accepted as an intermediate issuer, enabling certificate chain forgery. In lib/public_key…
Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be accepted as an intermediate issuer, enabling certificate chain forgery. In lib/public_key…
▾ Sunliterlang · erlang/otpEPSS 0.33%via NVD