CWE-347: CWE-347
Yearly Trend
Top Affected Vendors
All CWE-347 CVEs (181)
This critical authentication bypass vulnerability in pac4j-jwt allows attackers with the server's RSA public key to forge JWT authentication tokens an...
Mar 4, 2026CVE-2023-25574 is a critical authentication bypass vulnerability in jupyterhub-ltiauthenticator's LTI13Authenticator that fails to validate JWT signat...
Feb 25, 2025CVE-2024-45409 is a critical authentication bypass vulnerability in the Ruby SAML library where SAML response signatures are not properly verified. Th...
Sep 10, 2024xml-crypto versions 4.0.0 through 5.x have a critical signature validation bypass vulnerability. Attackers can forge XML signatures by replacing certi...
May 2, 2024This vulnerability in ecdsautils allows attackers to forge ECDSA signatures by providing zero-value signatures that are always considered valid. This ...
May 6, 2022CVE-2021-33885 allows remote unauthenticated attackers to send malicious data to B. Braun SpaceCom2 devices that will be accepted without cryptographi...
Aug 25, 2021This vulnerability in Hyperledger Aries Cloud Agent Python (ACA-Py) allows attackers to present forged verifiable credentials and enables malicious ve...
Jan 11, 2024This vulnerability in Fleet's Windows MDM enrollment flow allows attackers to bypass authentication by submitting forged JWT tokens that aren't proper...
Jan 21, 2026The OAuth Single Sign On plugin for WordPress has a critical authentication bypass vulnerability. Unauthenticated attackers can forge JWT tokens to ga...
Oct 4, 2025CVE-2025-8454 is a critical vulnerability in the uscan tool (part of devscripts) that allows attackers to bypass OpenPGP signature verification when u...
Aug 1, 2025CVE-2025-25291 is an authentication bypass vulnerability in ruby-saml that allows attackers to bypass SAML single sign-on authentication via signature...
Mar 12, 2025CVE-2025-27670 is a critical vulnerability in Vasion Print (formerly PrinterLogic) that allows attackers to bypass signature validation mechanisms. Th...
Mar 5, 2025An XML signature wrapping vulnerability in GitHub Enterprise Server's SAML authentication allows attackers with network access to forge SAML responses...
Aug 20, 2024This vulnerability in the CryptX Perl module allows attackers to bypass authentication and integrity checks in cryptographic operations. It affects ap...
Mar 18, 2024This vulnerability in Rockwell Automation FactoryTalk Service Platform allows attackers to steal service tokens and use them to authenticate to other ...
Jan 31, 2024This vulnerability in Studio Network Solutions ShareBrowser on macOS allows attackers to bypass signature verification, potentially enabling arbitrary...
Jan 17, 2024CVE-2016-20021 is a critical vulnerability in Gentoo Portage's emerge-webrsync tool that fails to validate PGP signatures on downloaded code. This all...
Jan 12, 2024This vulnerability allows remote attackers to gain root access to OMICRON StationGuard and StationScout systems by exploiting the update process with ...
Mar 23, 2023This vulnerability in ConnectWise Control (formerly ScreenConnect) allows attackers to modify signed executable files without invalidating their digit...
Feb 13, 2023Western Digital My Cloud devices running firmware before OS5 lack cryptographic signature verification for firmware updates, allowing attackers to upl...
Feb 6, 2023CVE-2022-31206 allows attackers to upload and execute arbitrary machine code on Omron SYSMAC PLCs due to lack of cryptographic authentication for down...
Jul 26, 2022CVE-2022-31053 is a critical authentication bypass vulnerability in Biscuit v1 tokens that allows attackers to forge valid gamma signatures, enabling ...
Jun 13, 2022This vulnerability allows attackers to forge digital signatures on arbitrary messages due to missing non-zero validation in the Stark Bank ECDSA libra...
Nov 9, 2021This vulnerability allows attackers to forge digital signatures on arbitrary messages by exploiting a missing non-zero check in the Stark Bank Java EC...
Nov 9, 2021This vulnerability in the Stark Bank Python ECDSA library allows attackers to forge digital signatures on arbitrary messages due to missing validation...
Nov 9, 2021CVE-2021-37160 is a critical firmware validation bypass vulnerability in Swisslog Healthcare Nexus Panel HMI3 Control Panel. It allows attackers to up...
Aug 2, 2021This vulnerability in tEnvoy's NaCl signature verification allows attackers to forge signatures by providing any invalid signature that matches the SH...
Jun 16, 2021This vulnerability in Apache Pulsar allows attackers to bypass JWT token authentication by using tokens with the 'none' algorithm, which are not prope...
May 26, 2021CVE-2021-3406 is a critical vulnerability in Keylime versions 5.8.1 and older that breaks the cryptographic chain of trust from hardware endorsement k...
Feb 25, 2021Linkr versions through 2.0.0 fail to verify the integrity of .linkr manifest files, allowing attackers to inject malicious file entries into package d...
Sep 16, 2025This vulnerability allows attackers to bypass SAML authentication in Zscaler's identity provider implementation by exploiting improper cryptographic s...
Aug 5, 2025This vulnerability allows unauthenticated attackers to upload malicious backup files to Quest KACE Systems Management Appliance due to weaknesses in s...
Jun 24, 2025CVE-2023-28801 is an improper cryptographic signature verification vulnerability in Zscaler's SAML authentication for the Admin UI. This allows attack...
Aug 31, 2023CVE-2025-40934 is a critical signature validation bypass vulnerability in XML-Sig Perl module versions 0.27 through 0.67. Attackers can remove signatu...
Nov 26, 2025This vulnerability in Misskey allows arbitrary users to impersonate any remote user due to missing signature validation in the decentralized social me...
Nov 29, 2023This vulnerability in Dex's SAML connector allows attackers to bypass XML signature validation through XML encoding issues in the underlying Go librar...
Dec 28, 2020The ruby-saml library contains an authentication bypass vulnerability due to XML parsing differences between ReXML and Nokogiri, allowing attackers to...
Dec 9, 2025The ruby-saml library versions up to 1.12.4 are vulnerable to authentication bypass via Signature Wrapping attacks. Attackers can exploit libxml2's ca...
Dec 9, 2025This vulnerability in gnark's signature verification allows signature malleability, enabling multiple distinct witnesses to satisfy the same public in...
Aug 22, 2025This vulnerability involves HP Linux Imaging and Printing Software using a weak DSA signing key for code signing, which could allow attackers to forge...
Jul 28, 2025CVE-2024-54150 is an algorithm confusion vulnerability in cjwt, a C JSON Web Token implementation. Attackers can forge JWT signatures by exploiting im...
Dec 19, 2024This vulnerability allows attackers to forge JWT tokens due to missing signature verification in DataEase. Attackers can gain unauthorized access to a...
Nov 7, 2024This vulnerability allows attackers to bypass SAML SSO authentication in GitHub Enterprise Server by exploiting improper cryptographic signature verif...
Oct 10, 2024This vulnerability in the Elliptic package for Node.js allows attackers to create multiple valid signatures for the same message due to BER-encoded si...
Aug 2, 2024This vulnerability allows attackers to bypass package name verification in the HwIms module, potentially disrupting services. It affects Huawei device...
Apr 8, 2024CVE-2023-34205 is a signature validation bypass vulnerability in Moov signedxml library. Attackers can manipulate XML signatures through signature wra...
May 30, 2023CVE-2020-35169 is an improper input validation vulnerability in Dell BSAFE cryptographic libraries that could allow attackers to execute arbitrary cod...
Jul 11, 2022This vulnerability allows attackers to bypass SAML SSO authentication in wire-server and impersonate any user with SAML credentials. It affects all wi...
Mar 16, 2022This vulnerability allows a privileged user to inject malicious code into IBM Power9 Self Boot Engine (SBE), bypassing firmware signature verification...
May 26, 2021This vulnerability in Portofino web framework allows attackers to forge valid JSON Web Tokens due to improper signature verification. This affects all...
Apr 16, 2021About CWE-347 (CWE-347)
Our database tracks 181 CVEs classified as CWE-347, with 54 rated critical and 91 rated high severity. The average CVSS score for CWE-347 vulnerabilities is 7.9.
External reference: View CWE-347 on MITRE CWE →
Monitor CWE-347 Vulnerabilities
Get alerted when new CWE-347 CVEs affect your infrastructure.
Start Monitoring Free