VulnSea

CWE-299

CVEs classified under CWE-299, newest first.

6 CVEsRSS

CVE-2026-93602Medium· 4.4
4d ago

rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints

rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints. At…

Sunlitrustls · webpkiEPSS 0.20%via NVD
CVE-2026-93493Medium· 5.9
4d ago

A flaw was found in Netty's `netty-handler-ssl-ocsp` component

A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by providing an Online Certificate Status Protocol (OCSP) response that omits the optional `nextUpdate` field. This omission…

SunlitRed Hat · netty-handler-ssl-ocspEPSS 0.22%via NVD
CVE-2026-86231Low· 3.7PoC
2w ago

A security flaw has been discovered in mwiede jsch up to 2.28.5

A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of the argument known_hosts results in improper…

Twilightmwiede · jschEPSS 0.27%via NVD
CVE-2026-61699High· 8.1PoC
2w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the blocklist never reaches an…

Midnightforgekeep · nebula-meshEPSS 0.25%via NVD
CVE-2026-56821High· 7.4
2mo ago

Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator

Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator

Twilightnetty · io.netty:netty-handler-ssl-ocspEPSS 0.16%via GHSA
GHSA-8f6j-263m-g72xMedium
2mo ago

Apple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks

Apple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks

Sunlitapp-store-server-library · app-store-server-libraryvia GHSA
CWE-299 vulnerabilities (CVEs) · VulnSea