Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-347 (密码学签名的验证不恰当) — Vulnerability Class 560

560 vulnerabilities classified as CWE-347 (密码学签名的验证不恰当). AI Chinese analysis included.

CWE-347 represents a critical integrity weakness where software fails to properly validate cryptographic signatures attached to data or code. Attackers typically exploit this flaw by intercepting communications or modifying stored files, substituting legitimate content with malicious payloads that lack valid digital signatures. Because the application accepts these unsigned or tampered inputs as authentic, it executes unauthorized commands or processes corrupted data, potentially leading to complete system compromise or data loss. To prevent this vulnerability, developers must implement rigorous verification routines that strictly check every incoming or processed item against its expected cryptographic signature using trusted public keys. This ensures that any alteration, even a single bit change, is detected and rejected. Additionally, employing secure key management practices and avoiding custom cryptographic implementations further strengthens the system’s defense against signature forgery and tampering attacks.

MITRE CWE Description
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Common Consequences (1)
Access Control, Integrity, Confidentiality Gain Privileges or Assume Identity, Modify Application Data, Execute Unauthorized Code or Commands
An attacker could gain access to sensitive data and possibly execute unauthorized code.
Examples (1)
In the following code, a JarFile object is created from a downloaded file.
File f = new File(downloadedFilePath); JarFile jf = new JarFile(f);
Bad · Java
CVE ID Title CVSS Severity Published
CVE-2026-108699 hyper-mcp through 0.8.3 Improper Signature Verification of OCI WebAssembly Plugins — hyper-mcp 6.5 Medium 2026-10-11
CVE-2026-106581 Docker Desktop for Windows installer failed to verify external packages — Docker Desktop 8.2 High 2026-10-09
CVE-2026-86405 Payment Validation Bypass in Sipay Electronic Money's SanalPos PrestaShop — PrestaShop Virtual POS Module 9.8 Critical 2026-10-09
CVE-2026-85531 Payment Validation Bypass in Sipay Electronic Money's OpenCart 3.x — OpenCart Virtual POS Module 9.8 Critical 2026-10-09
CVE-2026-107724 fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery — fast-jwt 7.4 High 2026-10-08
CVE-2026-107722 fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion — fast-jwt 9.8 Critical 2026-10-08
CVE-2026-14497 IBM DataPower Gateway Improper Verification of Cryptographic Signature — DataPower Gateway 10.6CD 8.1 High 2026-10-08
CVE-2026-14999 IBM DataPower Gateway Improper Verification of Cryptographic Signature — DataPower Gateway 10.6CD 7.4 High 2026-10-08
CVE-2026-76482 Cisco License On-Prem Security Hardening Release — Cisco License On-Prem 10.0 Critical 2026-10-07
CVE-2026-25302 Improper Verification of Cryptographic Signature in Boot — Snapdragon 7.1 High 2026-10-06
CVE-2026-77805 Weak Executable Signature Verification Vulnerability in Progress® Telerik® Fiddler® Classic — Progress® Telerik® Fiddler® Classic 7.9 High 2026-10-05
CVE-2026-105161 invariant-systems-ai aiir Policy Gate signature verification — aiir 5.3 Medium 2026-10-04
CVE-2026-105118 OpenAM before 16.1.3 Open Redirect via Unverified id_token_hint in endSession — OpenAM 4.7 Medium 2026-10-03
CVE-2026-71891 BLS12-381 key validation accepts a public key built on a foreign curve — BC-JAVA 7.1 High 2026-10-03
CVE-2026-71887 OpenPGP data signature accepted from a signing subkey without cross-certification — BC-JAVA 8.2 High 2026-10-03
CVE-2026-104437 Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling — zebra 7.4 High 2026-10-02
CVE-2026-104435 Zebra 4.4.0 Consensus Divergence via V5 SIGHASH_SINGLE Without Output — zebra 7.4 High 2026-10-02
CVE-2026-86326 协议网关固件签名验证绕过漏洞 — MGate MB3170 Series 8.6 High 2026-10-02
CVE-2026-63571 Attribute certificate path validation does not verify the attribute certificate's signature — bc-csharp 8.7 High 2026-10-02
CVE-2026-18397 SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability — SConnect 9.4 Critical 2026-10-01
CVE-2026-94212 Apache APISIX: unauthenticated impersonation issue in saml-auth — Apache APISIX 6.4 Medium 2026-10-01
CVE-2026-103245 n8n before 1.123.80, 2.39.6, and 2.40.1 Missing Webhook Signature Verification — n8n 5.3 Medium 2026-10-01
CVE-2026-87004 Tugtainer: OIDC id_token claims accepted without signature/audience/expiry verification — tugtainer 8.1 High 2026-09-30
CVE-2026-47554 NVIDIA Linux驱动内存压力下签名验证绕过漏洞 — GeForce 7.1 High 2026-09-30
CVE-2026-102508 Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade — Apache PLC4X 9.2 Critical 2026-09-30
CVE-2026-91191 Lantronix G520 Series Cellular Gateway Improper Verification of Cryptographic Signature — G520 Series 7.5 High 2026-09-29
CVE-2026-100293 Improper verification of cryptographic signature in Anjvision YSSD-RTMP-H5 — YSSD-RTMP-H5 8.8 High 2026-09-29
CVE-2026-102273 PyJWT accepts public JWK containers as HMAC secrets — pyjwt 7.4 High 2026-09-28
CVE-2026-102272 PyJWT BOM Bypass — pyjwt 7.4 High 2026-09-28
CVE-2026-102271 PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard — pyjwt 7.4 High 2026-09-28

Vulnerabilities classified as CWE-347 (密码学签名的验证不恰当) represent 560 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.