CWE-354: Improper Validation of Integrity Check Value
The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.
93 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-11543 — Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may c
- CVE-2026-33026 — nginx-ui Backup Restore Allows Tampering with Encrypted Backups
- CVE-2025-7096 — Comodo Internet Security Premium Manifest File cis_update_x64.xml integrity check
- CVE-2025-54887 — jwe: Missing AES-GCM authentication tag validation in encrypted JWEs
- CVE-2026-26928 — Lack of Dynamic Library Validation in SzafirHost
- CVE-2024-48930 — secp256k1-node vulnerable to private key extraction over ECDH
- CVE-2024-47089 — Unauthorized Transaction Manipulation Vulnerability
- CVE-2026-32600 — xml-security is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
- CVE-2026-32313 — xmlseclibs is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
- CVE-2026-31839 — Striae has a hash validation utility vulnerability
- CVE-2026-13385 — An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows
- CVE-2024-46992 — Electron ASAR Integrity bypass by just modifying the content
- CVE-2026-32105 — xrdp: RDP MAC signature (dataSignature) never verified on receive — integrity bypass in non-TLS mode
- CVE-2024-32883 — MCUboot Injection attack of unprotected TLV values
- CVE-2026-75803 — AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()
- CVE-2026-32303 — Cryptomator: Tampered vault configuration allows MITM attack on Hub API
- CVE-2024-34714 — Hoppscotch Extension responds to calls made by origins not in the domain list
- CVE-2026-75625 — Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass
- CVE-2026-34182 — CMS AuthEnvelopedData Processing May Accept Forged Messages
- CVE-2026-26275 — httpsig-hyper has Improper Digest Verification that May Allow Message Integrity Bypass
Recently published
- CVE-2026-20354 — Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty
- CVE-2026-82549 — Linux Foundation Magma SecurityModeComplete integrity check
- CVE-2026-75803 — AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()
- CVE-2026-75625 — Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass
- CVE-2026-12817 — OpenPGP AEAD decryption skips final tag on chunk-aligned data
- CVE-2026-12816 — IESEngine stream-mode MAC forgery via length-dependent KDF split
- CVE-2026-12803 — KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery)
- CVE-2026-12802 — CMS AuthEnvelopedData fails to enforce tag-length on decryption
- CVE-2026-58061 — CCM-family modes write plaintext to caller buffer before tag check
- CVE-2026-59642 — CMS AuthenticatedData content not bound to MAC when authAttrs present
- CVE-2026-56416 — Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name
- CVE-2026-16317 — Silent Drop of TLS 1.3 Encrypted Records in s2n-tls
- CVE-2026-13385 — An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows
- CVE-2026-9653 — 1756-EN2, 1756-EN3, and 1756-ENBT - Denial of Service via CIP Connection ID
- CVE-2026-8720 — HMAC-BLAKE2 final discards message when key length exceeds block size
- CVE-2026-50021 — pnpm: Integrity Check Bypass via Missing Lockfile Integrity Field
- CVE-2026-50128 — Mastodon: Spoofing of attribution domains
- CVE-2026-48028 — Mastodon: Removal of integrity-protected JSON entries from signed activities
- CVE-2026-49230 — Apache APISIX: Authentication bypass in jwe-decrypt
- CVE-2025-11694 — Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities