SiteShadow
Back to vulnerability library
Detected byCWE-aware static analysis

CWE-295 Improper Certificate Validation

Coverage: 23 rules in the SiteShadow rule registry target this CWE (registry v2.0.0). Regex 15Other-pattern 8 Also: Taint and heuristic analyzers may also detect related flows (see coverage for the authoritative list) Registry tagging shows intent, for sample-level behaviour and benchmarked gaps see known gaps.

What this means

SiteShadow flagged TLS usage where certificate validation is missing, incomplete, or overridden (accepting invalid certs, skipping hostname checks, trusting any certificate).

Why it matters

Improper validation can enable interception or tampering.

Safer examples

1) Keep verification enabled by default

Avoid disabling verification flags; rely on defaults unless you have a controlled reason.

2) Fix trust store/CA issues properly

3) If you need custom trust, scope it tightly

Pin only the required internal CA(s) and never turn verification off globally (see CERT01 / T01).

How SiteShadow detects it (high level)

References

---

← Back to Vulnerability Library

Catch this in your code with SiteShadow.

Every released SiteShadow scanner is free, including full project analysis, reports, patterns, dashboard access, and configured organization SSO.