SiteShadow
Back to vulnerability library

CWE-295 Improper Certificate Validation

What this means

SiteShadow flagged TLS usage where certificate validation is missing, incomplete, or overridden (accepting invalid certs, skipping hostname checks, trusting any certificate).

Why it matters

Improper validation can enable interception or tampering.

Safer examples

1) Keep verification enabled by default

Avoid disabling verification flags; rely on defaults unless you have a controlled reason.

2) Fix trust store/CA issues properly

3) If you need custom trust, scope it tightly

Pin only the required internal CA(s) and never turn verification off globally (see CERT01 / T01).

How SiteShadow detects it (high level)

References

---

← Back to Vulnerability Library

Request access View coverage