CWE-298: Improper Validation of Certificate Expiration

low-risk

A certificate expiration is not validated or is incorrectly validated, so trust may be assigned to certificates that have been abandoned due to age.

Abstraction: Variant

Common Consequences

Integrity Other
Authentication Other

Real-World Examples (4)

CVE CVSS EPSS KEV
CVE-2023-42446 6.5 0.1%
CVE-2025-67109 10.0 0.1%
CVE-2025-59036 5.5 0.1%
CVE-2025-67108 10.0 0.0%
0
/ 100
low-risk
Active Threat 0/50 · Minimal
Exploit Availability 0/50 · Minimal