CWE-757: Algorithm Downgrade
A protocol or its implementation supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties.
32 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-4995 — Protocol Downgrade in Wapro ERP Desktop
- CVE-2026-72889 — Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify
- CVE-2026-72887 — Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token
- CVE-2025-10693 — Silicon Labs Z-Wave PIR Sensor Joins Network as Non-Secure
- CVE-2026-55953 — TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication
- CVE-2026-18691 — Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure
- CVE-2024-23656 — Dex 2.37.0 is discarding TLSconfig and always serves deprecated TLS 1.0/1.1 and insecure ciphers
- CVE-2026-54291 — Silent channel-binding authentication downgrade via unsupported certificate algorithms
- CVE-2026-53712 — SCRAM: Silent channel-binding authentication downgrade via unsupported certificate algorithms
- CVE-2026-32650 — Anviz CrossChex Standard Algorithm Downgrade
- CVE-2026-2673 — OpenSSL TLS 1.3 server may choose unexpected key agreement group
- CVE-2026-48747 — Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade
- CVE-2026-4942 — IBM i is Affected by Algorithm Downgrade in Transport Layer Security []
- CVE-2025-36582 — Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorit
- CVE-2026-6550 — Key commitment policy bypass via shared key cache in AWS Encryption SDK for Python
- CVE-2026-1677 — net: TLS 1.2 connections allowed on TLS 1.3 sockets
- CVE-2025-59270 — psPAS does not enforce TLS 1.2 within Get-PASSAMLResponse
- CVE-2026-54780 — CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
- CVE-2026-6092 — Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configured
- CVE-2024-20069 — In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade che
Recently published
- CVE-2026-72889 — Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify
- CVE-2026-72887 — Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token
- CVE-2026-18691 — Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure
- CVE-2026-55953 — TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication
- CVE-2026-4942 — IBM i is Affected by Algorithm Downgrade in Transport Layer Security []
- CVE-2026-53712 — SCRAM: Silent channel-binding authentication downgrade via unsupported certificate algorithms
- CVE-2026-48747 — Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade
- CVE-2026-54780 — CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
- CVE-2026-54291 — Silent channel-binding authentication downgrade via unsupported certificate algorithms
- CVE-2026-6092 — Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configured
- CVE-2026-1677 — net: TLS 1.2 connections allowed on TLS 1.3 sockets
- CVE-2026-6550 — Key commitment policy bypass via shared key cache in AWS Encryption SDK for Python
- CVE-2026-32650 — Anviz CrossChex Standard Algorithm Downgrade
- CVE-2026-2673 — OpenSSL TLS 1.3 server may choose unexpected key agreement group
- CVE-2025-10693 — Silicon Labs Z-Wave PIR Sensor Joins Network as Non-Secure
- CVE-2025-59270 — psPAS does not enforce TLS 1.2 within Get-PASSAMLResponse
- CVE-2025-36582 — Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorit
- CVE-2024-4995 — Protocol Downgrade in Wapro ERP Desktop
- CVE-2024-20069 — In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade che
- CVE-2024-23656 — Dex 2.37.0 is discarding TLSconfig and always serves deprecated TLS 1.0/1.1 and insecure ciphers