CWE-299: Improper Check for Certificate Revocation
The product does not check or incorrectly checks the revocation status of a certificate, which may cause it to use a certificate that has been compromised.
13 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-4428 — CRL Distribution Point Scope Check Logic Error in AWS-LC
- CVE-2025-11955 — Incorrect validation of OCSP certificates in TheGreenBow VPN Client Windows Enterprise
- CVE-2025-3085 — MongoDB Server running on Linux may allow unexpected connections where intermediate certificates are revoked
- CVE-2026-9636 — Rockwell Automation CompactLogix® 5380 ControlLogix® 5580 / 1756-EN4 Communications Module – Certificate Revocation List Vulnerability
- CVE-2026-61699 — nebula-mesh: Certificate revocation is never enforced at the mesh
- CVE-2026-56821 — Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
- CVE-2026-86231 — mwiede jsch KnownHosts.java getRevokedKeys improper check for certificate revocation
- CVE-2025-36057 — IBM Cognos Analytics Mobile (iOS) authentication bypass
- CVE-2026-6899 — Improper Check for Certificate Revocation in S2OPC
- CVE-2024-56138 — Timestamp signature generation lacks certificate revocation check in notion-go
Recently published
- CVE-2026-86231 — mwiede jsch KnownHosts.java getRevokedKeys improper check for certificate revocation
- CVE-2026-61699 — nebula-mesh: Certificate revocation is never enforced at the mesh
- CVE-2026-56821 — Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
- CVE-2026-9636 — Rockwell Automation CompactLogix® 5380 ControlLogix® 5580 / 1756-EN4 Communications Module – Certificate Revocation List Vulnerability
- CVE-2026-6899 — Improper Check for Certificate Revocation in S2OPC
- CVE-2026-4428 — CRL Distribution Point Scope Check Logic Error in AWS-LC
- CVE-2025-11955 — Incorrect validation of OCSP certificates in TheGreenBow VPN Client Windows Enterprise
- CVE-2025-36057 — IBM Cognos Analytics Mobile (iOS) authentication bypass
- CVE-2025-3085 — MongoDB Server running on Linux may allow unexpected connections where intermediate certificates are revoked
- CVE-2024-56138 — Timestamp signature generation lacks certificate revocation check in notion-go
More specific weaknesses
- CWE-370 — Missing Check for Certificate Revocation after Initial Check