Known Vulnerabilities for Validation Authority by Tumbleweed
Listed below are 10 of the newest known vulnerabilities associated with "Validation Authority" by "Tumbleweed".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-92943 json | Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Pytho... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-92939 json | vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The ... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-86881 json | A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and iPadOS... | Not Provided | 2026-09-14 | 2026-09-16 |
| CVE-2026-85221 json | MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer property was no... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-85088 json | Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift. Both libraries install ... | Not Provided | 2026-10-02 | 2026-10-02 |
| CVE-2026-84303 json | gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/... | Not Provided | 2026-09-01 | 2026-09-02 |
| CVE-2026-82750 json | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-... | Not Provided | 2026-09-06 | 2026-09-08 |
| CVE-2026-82380 json | Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-in user to perform state-... | Not Provided | 2026-09-28 | 2026-09-28 |
| CVE-2026-75899 json | fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hos... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-75458 json | The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open Source Exam System <= 3.9.0 contains a vertical... | Not Provided | 2026-08-31 | 2026-09-01 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tumbleweed | Validation Authority | 4.9 | |||
| Application | Tumbleweed | Validation Authority | 4.11.0 | |||
| Application | Tumbleweed | Validation Authority | 4.10.6 | |||
| Application | Tumbleweed | Validation Authority | 1.0.0 | |||
| Application | Tumbleweed | Validation Authority | 1.0 |