CWE-295
AllowedImproper Certificate Validation
Abstraction: Base · Status: Draft
The product does not validate, or incorrectly validates, a certificate.
2267 vulnerabilities reference this CWE, most recent first.
GHSA-VX9H-7FRF-374V
Vulnerability from github – Published: 2024-10-18 09:31 – Updated: 2024-10-22 18:32A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software trusts a certificate issued by an entity that isn't authorized to issue certificates. This occurs when the "Basic Constraints" extension in the certificate indicates that it is meant to be an "End Entity”. This flaw could allow an attacker to perform a Man-in-the-Middle (MITM) attack, intercepting and potentially altering communications between the user and the website.
{
"affected": [],
"aliases": [
"CVE-2023-49570"
],
"database_specific": {
"cwe_ids": [
"CWE-295"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-18T09:15:02Z",
"severity": "HIGH"
},
"details": "A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software trusts a certificate issued by an entity that isn\u0027t authorized to issue certificates. This occurs when the \"Basic Constraints\" extension in the certificate indicates that it is meant to be an \"End Entity\u201d. This flaw could allow an attacker to perform a Man-in-the-Middle (MITM) attack, intercepting and potentially altering communications between the user and the website.",
"id": "GHSA-vx9h-7frf-374v",
"modified": "2024-10-22T18:32:05Z",
"published": "2024-10-18T09:31:26Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49570"
},
{
"type": "WEB",
"url": "https://www.bitdefender.com/support/security-advisories/insecure-trust-of-basic-constraints-certificate-in-bitdefender-total-security-https-scanning-va-11210"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-VXF6-WWJR-WQH4
Vulnerability from github – Published: 2022-05-24 16:45 – Updated: 2024-04-04 00:28A vulnerability in the Secure Shell (SSH) authentication process of Cisco Small Business Switches software could allow an attacker to bypass client-side certificate authentication and revert to password authentication. The vulnerability exists because OpenSSH mishandles the authentication process. An attacker could exploit this vulnerability by attempting to connect to the device via SSH. A successful exploit could allow the attacker to access the configuration as an administrative user if the default credentials are not changed. There are no workarounds available; however, if client-side certificate authentication is enabled, disable it and use strong password authentication. Client-side certificate authentication is disabled by default.
{
"affected": [],
"aliases": [
"CVE-2019-1859"
],
"database_specific": {
"cwe_ids": [
"CWE-285",
"CWE-295"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2019-05-03T17:29:00Z",
"severity": "HIGH"
},
"details": "A vulnerability in the Secure Shell (SSH) authentication process of Cisco Small Business Switches software could allow an attacker to bypass client-side certificate authentication and revert to password authentication. The vulnerability exists because OpenSSH mishandles the authentication process. An attacker could exploit this vulnerability by attempting to connect to the device via SSH. A successful exploit could allow the attacker to access the configuration as an administrative user if the default credentials are not changed. There are no workarounds available; however, if client-side certificate authentication is enabled, disable it and use strong password authentication. Client-side certificate authentication is disabled by default.",
"id": "GHSA-vxf6-wwjr-wqh4",
"modified": "2024-04-04T00:28:19Z",
"published": "2022-05-24T16:45:10Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-1859"
},
{
"type": "WEB",
"url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-scbv"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-W293-VG96-WGC3
Vulnerability from github – Published: 2026-09-29 18:17 – Updated: 2026-09-29 18:17Impact
undici's BalancedPool passes its constructor options through a JSON-based deep clone (JSON.parse(JSON.stringify(...))) before forwarding them to each per-upstream Pool. JSON cannot represent functions, so a caller-supplied connect or tls option containing a checkServerIdentity callback (or a custom connector function) is silently dropped before it reaches the TLS layer. As a result, a TLS peer whose certificate a custom checkServerIdentity was written to reject, but which passes Node's default hostname and chain checks, is silently accepted when the request is made through BalancedPool. Client, Pool, Agent, and RoundRobinPool destructure connect/tls before the clone and are not affected. Only applications that use BalancedPool with a function-valued connect/tls option (such as a custom checkServerIdentity or connector) are affected.
Patches
Upgrade to 7.29.1 or 8.10.2. BalancedPool now preserves the connect and tls options outside the JSON clone, so custom TLS verification callbacks are forwarded to each upstream unchanged.
Workarounds
Use Client, Pool, or Agent instead of BalancedPool for connections that rely on a custom checkServerIdentity or connector, until upgraded.
{
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "undici"
},
"ranges": [
{
"events": [
{
"introduced": "7.24.1"
},
{
"fixed": "7.29.1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "npm",
"name": "undici"
},
"ranges": [
{
"events": [
{
"introduced": "8.0.0"
},
{
"fixed": "8.10.2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-84961"
],
"database_specific": {
"cwe_ids": [
"CWE-295"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-29T18:17:15Z",
"nvd_published_at": "2026-09-04T17:17:02Z",
"severity": "HIGH"
},
"details": "### Impact\n\nundici\u0027s `BalancedPool` passes its constructor options through a JSON-based deep clone (`JSON.parse(JSON.stringify(...))`) before forwarding them to each per-upstream `Pool`. JSON cannot represent functions, so a caller-supplied `connect` or `tls` option containing a `checkServerIdentity` callback (or a custom connector function) is silently dropped before it reaches the TLS layer. As a result, a TLS peer whose certificate a custom `checkServerIdentity` was written to reject, but which passes Node\u0027s default hostname and chain checks, is silently accepted when the request is made through `BalancedPool`. `Client`, `Pool`, `Agent`, and `RoundRobinPool` destructure `connect`/`tls` before the clone and are not affected. Only applications that use `BalancedPool` with a function-valued `connect`/`tls` option (such as a custom `checkServerIdentity` or connector) are affected.\n\n### Patches\n\nUpgrade to `7.29.1` or `8.10.2`. `BalancedPool` now preserves the `connect` and `tls` options outside the JSON clone, so custom TLS verification callbacks are forwarded to each upstream unchanged.\n\n### Workarounds\n\nUse `Client`, `Pool`, or `Agent` instead of `BalancedPool` for connections that rely on a custom `checkServerIdentity` or connector, until upgraded.",
"id": "GHSA-w293-vg96-wgc3",
"modified": "2026-09-29T18:17:15Z",
"published": "2026-09-29T18:17:15Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84961"
},
{
"type": "WEB",
"url": "https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390"
},
{
"type": "WEB",
"url": "https://github.com/nodejs/undici/commit/f690157d728508652fef14673630c71515123e96"
},
{
"type": "WEB",
"url": "https://cna.openjsf.org/security-advisories.html"
},
{
"type": "PACKAGE",
"url": "https://github.com/nodejs/undici"
},
{
"type": "WEB",
"url": "https://github.com/nodejs/undici/releases/tag/v7.29.1"
},
{
"type": "WEB",
"url": "https://github.com/nodejs/undici/releases/tag/v8.10.2"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool"
}
GHSA-W2JC-6HPR-7CWC
Vulnerability from github – Published: 2022-05-24 17:46 – Updated: 2022-05-24 17:46The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validation of the ITM Server's certificate, which enables a remote attacker to intercept and alter these communications using a man-in-the-middle attack. All versions before 7.11.1 are affected. Agents for Windows and Cloud are not affected.
{
"affected": [],
"aliases": [
"CVE-2021-27899"
],
"database_specific": {
"cwe_ids": [
"CWE-295"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2021-04-06T21:15:00Z",
"severity": "HIGH"
},
"details": "The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validation of the ITM Server\u0027s certificate, which enables a remote attacker to intercept and alter these communications using a man-in-the-middle attack. All versions before 7.11.1 are affected. Agents for Windows and Cloud are not affected.",
"id": "GHSA-w2jc-6hpr-7cwc",
"modified": "2022-05-24T17:46:37Z",
"published": "2022-05-24T17:46:37Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-27899"
},
{
"type": "WEB",
"url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2021-0004"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-W2VR-G8CH-FVGC
Vulnerability from github – Published: 2026-09-18 21:32 – Updated: 2026-09-18 21:32IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.
{
"affected": [],
"aliases": [
"CVE-2026-84081"
],
"database_specific": {
"cwe_ids": [
"CWE-295"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-09-18T20:17:27Z",
"severity": "HIGH"
},
"details": "IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.",
"id": "GHSA-w2vr-g8ch-fvgc",
"modified": "2026-09-18T21:32:26Z",
"published": "2026-09-18T21:32:26Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84081"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7288035"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-W2W6-XP88-5CVW
Vulnerability from github – Published: 2023-03-22 18:30 – Updated: 2025-05-05 18:32A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the -policy' argument to the command line utilities or by calling theX509_VERIFY_PARAM_set1_policies()' function.
{
"affected": [],
"aliases": [
"CVE-2023-0464"
],
"database_specific": {
"cwe_ids": [
"CWE-295"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-03-22T17:15:00Z",
"severity": "HIGH"
},
"details": "A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the `-policy\u0027 argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()\u0027 function.",
"id": "GHSA-w2w6-xp88-5cvw",
"modified": "2025-05-05T18:32:35Z",
"published": "2023-03-22T18:30:37Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0464"
},
{
"type": "WEB",
"url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2017771e2db3e2b96f89bbe8766c3209f6a99545"
},
{
"type": "WEB",
"url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2dcd4f1e3115f38cefa43e3efbe9b801c27e642e"
},
{
"type": "WEB",
"url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=879f7080d7e141f415c79eaa3a8ac4a3dad0348b"
},
{
"type": "WEB",
"url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=959c59c7a0164117e7f8366466a32bb1f8d77ff1"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202402-08"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230406-0006"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240621-0006"
},
{
"type": "WEB",
"url": "https://www.couchbase.com/alerts"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5417"
},
{
"type": "WEB",
"url": "https://www.openssl.org/news/secadv/20230322.txt"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-W2XR-JMHW-CV64
Vulnerability from github – Published: 2022-05-17 02:51 – Updated: 2022-05-17 02:51There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398.
{
"affected": [],
"aliases": [
"CVE-2016-9319"
],
"database_specific": {
"cwe_ids": [
"CWE-295"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2017-03-31T00:59:00Z",
"severity": "MODERATE"
},
"details": "There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398.",
"id": "GHSA-w2xr-jmhw-cv64",
"modified": "2022-05-17T02:51:54Z",
"published": "2022-05-17T02:51:54Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2016-9319"
},
{
"type": "WEB",
"url": "https://success.trendmicro.com/solution/1116973"
},
{
"type": "WEB",
"url": "http://www.info-sec.ca/advisories/Trend-Micro-Enterprise-Mobile-Security.html"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/97272"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-W34Q-CM8F-9C5X
Vulnerability from github – Published: 2026-09-17 20:31 – Updated: 2026-09-17 20:31Summary
The OTLP log gRPC exporter loads TLS settings from environment variables but does not apply them when creating gRPC transport credentials. Operators who rely on OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, or related client certificate variables for CA pinning or mTLS get a connection that falls back to system roots and omits the env-supplied client certificate. A network attacker who can intercept or spoof the collector connection with a system-trusted certificate can read or alter log telemetry.
Introduced in commit: d99c76f
Details
The affected code is in exporters/otlp/otlplog/otlploggrpc.
newConfig resolves env-based TLS configuration into cfg.tlsCfg at exporters/otlp/otlplog/otlploggrpc/config.go:106-116. The finding also identifies loadEnvTLS at config.go:451-492 as the code that builds a *tls.Config containing RootCAs and client certificates from OTEL_EXPORTER_OTLP[_LOGS]_CERTIFICATE and OTEL_EXPORTER_OTLP[_LOGS]_CLIENT_CERTIFICATE/KEY.
However, newGRPCDialOptions in exporters/otlp/otlplog/otlploggrpc/client.go:83-92 only checks cfg.gRPCCredentials and cfg.insecure. When neither is set, which is the normal env-only TLS configuration path, it uses credentials.NewTLS(nil). That default trusts the host system root CAs and contains no env-supplied client certificate. The finding evidence reports no other tlsCfg use in the package, so env-based CA pinning and mTLS settings are loaded but not enforced.
PoC
The validation artifact contains a ready-to-run test at validation-artifact.zip:./poc_env_tls_ignored_test.go and brief instructions at validation-artifact.zip:./README.md.
From a checkout of pellared/opentelemetry-go at commit d99c76f, with Go module dependencies available:
FINDING_DIR=/path/to/02-e6e2897a969c8191b260f243fbc99ebd-log-grpc-exporter-ignores-env-tls-certs-bypassing-mtls-pinning
cd /path/to/opentelemetry-go
git checkout d99c76f
tar -xOf validation-artifact.tar ./poc_env_tls_ignored_test.go > exporters/otlp/otlplog/otlploggrpc/poc_env_tls_ignored_test.go
cd exporters/otlp/otlplog/otlploggrpc
GO111MODULE=on go test -v -run TestEnvTLSIgnored -count=1
The test generates a private CA and a TLS gRPC logs server certificate signed by that CA. It sets:
OTEL_EXPORTER_OTLP_LOGS_ENDPOINT=https://127.0.0.1:<test-port>
OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE=<temp-dir>/ca.pem
Expected output includes an unknown authority failure for the first export call even though the env certificate points to the server CA, followed by a passing test after the same cfg.tlsCfg is explicitly wired through WithTLSCredentials:
=== RUN TestEnvTLSIgnored
poc_env_tls_ignored_test.go:...: export error (expected due to ignored tlsCfg): ... x509: certificate signed by unknown authority
--- PASS: TestEnvTLSIgnored
PASS
This demonstrates that the env CA is parsed into cfg.tlsCfg but ignored by the default gRPC dial path.
Impact
This is improper TLS certificate validation and endpoint authentication caused by ignoring configured trust material. Users of the OTLP log gRPC exporter who configure TLS, CA pinning, or mTLS through environment variables are impacted when they do not also supply explicit WithTLSCredentials. TLS still occurs with system roots, but the intended private CA pinning and client certificate authentication are bypassed. An attacker with a suitable network position and a system-trusted certificate for the collector endpoint can intercept or tamper with log telemetry that operators expected to be protected by the configured CA or mTLS policy.
{
"affected": [
{
"package": {
"ecosystem": "Go",
"name": "go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.21.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-81871"
],
"database_specific": {
"cwe_ids": [
"CWE-295",
"CWE-923"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-17T20:31:09Z",
"nvd_published_at": "2026-09-16T21:17:22Z",
"severity": "MODERATE"
},
"details": "### Summary\n\nThe OTLP log gRPC exporter loads TLS settings from environment variables but does not apply them when creating gRPC transport credentials. Operators who rely on `OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE`, `OTEL_EXPORTER_OTLP_CERTIFICATE`, or related client certificate variables for CA pinning or mTLS get a connection that falls back to system roots and omits the env-supplied client certificate. A network attacker who can intercept or spoof the collector connection with a system-trusted certificate can read or alter log telemetry. \n\nIntroduced in commit: d99c76f\n\n### Details\n\nThe affected code is in `exporters/otlp/otlplog/otlploggrpc`.\n\n`newConfig` resolves env-based TLS configuration into `cfg.tlsCfg` at `exporters/otlp/otlplog/otlploggrpc/config.go:106-116`. The finding also identifies `loadEnvTLS` at `config.go:451-492` as the code that builds a `*tls.Config` containing `RootCAs` and client certificates from `OTEL_EXPORTER_OTLP[_LOGS]_CERTIFICATE` and `OTEL_EXPORTER_OTLP[_LOGS]_CLIENT_CERTIFICATE`/`KEY`.\n\nHowever, `newGRPCDialOptions` in `exporters/otlp/otlplog/otlploggrpc/client.go:83-92` only checks `cfg.gRPCCredentials` and `cfg.insecure`. When neither is set, which is the normal env-only TLS configuration path, it uses `credentials.NewTLS(nil)`. That default trusts the host system root CAs and contains no env-supplied client certificate. The finding evidence reports no other `tlsCfg` use in the package, so env-based CA pinning and mTLS settings are loaded but not enforced.\n\n### PoC\n\n[validation-artifact.zip](https://github.com/user-attachments/files/27493589/validation-artifact.zip)\n\n\nThe validation artifact contains a ready-to-run test at `validation-artifact.zip:./poc_env_tls_ignored_test.go` and brief instructions at `validation-artifact.zip:./README.md`.\n\nFrom a checkout of `pellared/opentelemetry-go` at commit `d99c76f`, with Go module dependencies available:\n\n```sh\nFINDING_DIR=/path/to/02-e6e2897a969c8191b260f243fbc99ebd-log-grpc-exporter-ignores-env-tls-certs-bypassing-mtls-pinning\ncd /path/to/opentelemetry-go\ngit checkout d99c76f\ntar -xOf validation-artifact.tar ./poc_env_tls_ignored_test.go \u003e exporters/otlp/otlplog/otlploggrpc/poc_env_tls_ignored_test.go\ncd exporters/otlp/otlplog/otlploggrpc\nGO111MODULE=on go test -v -run TestEnvTLSIgnored -count=1\n```\n\nThe test generates a private CA and a TLS gRPC logs server certificate signed by that CA. It sets:\n\n```sh\nOTEL_EXPORTER_OTLP_LOGS_ENDPOINT=https://127.0.0.1:\u003ctest-port\u003e\nOTEL_EXPORTER_OTLP_LOGS_CERTIFICATE=\u003ctemp-dir\u003e/ca.pem\n```\n\nExpected output includes an `unknown authority` failure for the first export call even though the env certificate points to the server CA, followed by a passing test after the same `cfg.tlsCfg` is explicitly wired through `WithTLSCredentials`:\n\n```text\n=== RUN TestEnvTLSIgnored\n poc_env_tls_ignored_test.go:...: export error (expected due to ignored tlsCfg): ... x509: certificate signed by unknown authority\n--- PASS: TestEnvTLSIgnored\nPASS\n```\n\nThis demonstrates that the env CA is parsed into `cfg.tlsCfg` but ignored by the default gRPC dial path.\n\n### Impact\n\nThis is improper TLS certificate validation and endpoint authentication caused by ignoring configured trust material. Users of the OTLP log gRPC exporter who configure TLS, CA pinning, or mTLS through environment variables are impacted when they do not also supply explicit `WithTLSCredentials`. TLS still occurs with system roots, but the intended private CA pinning and client certificate authentication are bypassed. An attacker with a suitable network position and a system-trusted certificate for the collector endpoint can intercept or tamper with log telemetry that operators expected to be protected by the configured CA or mTLS policy.",
"id": "GHSA-w34q-cm8f-9c5x",
"modified": "2026-09-17T20:31:09Z",
"published": "2026-09-17T20:31:09Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w34q-cm8f-9c5x"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81871"
},
{
"type": "WEB",
"url": "https://github.com/open-telemetry/opentelemetry-go/commit/c65d435b43e5e6b82310e6b18dd4cdcb8ac63a0c"
},
{
"type": "PACKAGE",
"url": "https://github.com/open-telemetry/opentelemetry-go"
},
{
"type": "WEB",
"url": "https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/otlp/otlplog/otlploggrpc/v0.21.0"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
"type": "CVSS_V4"
}
],
"summary": "OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning"
}
GHSA-W3J6-8J34-Q43X
Vulnerability from github – Published: 2022-05-17 05:39 – Updated: 2024-09-13 14:18libcloud before 0.4.0 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack. This is due to an upstream issue with python's SSL module rather than directly with libcloud.
{
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "apache-libcloud"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.4.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2010-4340"
],
"database_specific": {
"cwe_ids": [
"CWE-295"
],
"github_reviewed": true,
"github_reviewed_at": "2024-02-23T20:59:34Z",
"nvd_published_at": "2011-09-12T12:41:00Z",
"severity": "HIGH"
},
"details": "libcloud before 0.4.0 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack. This is due to an upstream issue with python\u0027s SSL module rather than directly with libcloud.",
"id": "GHSA-w3j6-8j34-q43x",
"modified": "2024-09-13T14:18:40Z",
"published": "2022-05-17T05:39:24Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2010-4340"
},
{
"type": "WEB",
"url": "https://github.com/apache/libcloud/commit/87ee61e6ba03a43dcefea2ce180988bec066b6fd"
},
{
"type": "WEB",
"url": "https://bugs.python.org/issue1589"
},
{
"type": "PACKAGE",
"url": "https://github.com/apache/libcloud"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/apache-libcloud/PYSEC-2011-24.yaml"
},
{
"type": "WEB",
"url": "https://issues.apache.org/jira/browse/LIBCLOUD-55"
},
{
"type": "WEB",
"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=598463"
},
{
"type": "WEB",
"url": "http://mail-archives.apache.org/mod_mbox/incubator-libcloud/201009.mbox/%3C5860913.463891285776633273.JavaMail.jira@thor%3E"
},
{
"type": "WEB",
"url": "http://mail-archives.apache.org/mod_mbox/incubator-libcloud/201011.mbox/browser"
},
{
"type": "WEB",
"url": "http://wiki.apache.org/incubator/LibcloudSSL"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
"type": "CVSS_V4"
}
],
"summary": "Apache Libcloud does not verify SSL certificates for HTTPS connections"
}
GHSA-W3W5-RFWV-898Q
Vulnerability from github – Published: 2026-05-26 13:30 – Updated: 2026-05-26 13:30Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information tampering.
{
"affected": [],
"aliases": [
"CVE-2025-32745"
],
"database_specific": {
"cwe_ids": [
"CWE-295"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-05-22T14:16:24Z",
"severity": "MODERATE"
},
"details": "Dell PowerFlex Manager, version(s) \u003c=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information tampering.",
"id": "GHSA-w3w5-rfwv-898q",
"modified": "2026-05-26T13:30:16Z",
"published": "2026-05-26T13:30:16Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32745"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000391392/dsa-2025-434-security-update-for-dell-powerflex-appliance-multiple-third-party-component-vulnerabilities"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000391568/dsa-2025-435-security-update-for-dell-powerflex-rack-multiple-third-party-component-vulnerabilities"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"type": "CVSS_V3"
}
]
}
Mitigation
Certificates should be carefully managed and checked to assure that data are encrypted with the intended owner's public key.
Mitigation
If certificate pinning is being used, ensure that all relevant properties of the certificate are fully validated before the certificate is pinned, including the hostname.
CAPEC-459: Creating a Rogue Certification Authority Certificate
An adversary exploits a weakness resulting from using a hashing algorithm with weak collision resistance to generate certificate signing requests (CSR) that contain collision blocks in their "to be signed" parts. The adversary submits one CSR to be signed by a trusted certificate authority then uses the signed blob to make a second certificate appear signed by said certificate authority. Due to the hash collision, both certificates, though different, hash to the same value and so the signed blob works just as well in the second certificate. The net effect is that the adversary's second X.509 certificate, which the Certification Authority has never seen, is now signed and validated by that Certification Authority.
CAPEC-475: Signature Spoofing by Improper Validation
An adversary exploits a cryptographic weakness in the signature verification algorithm implementation to generate a valid signature without knowing the key.