Certifi is a focused Python package that maintains a curated bundle of certificate authority root certificates for use in HTTPS validation and trust verification. The package's observed vulnerability signal centers on the mechanism of certificate authenticity verification itself, with exposure rooted in improper or insufficient validation of certificate data integrity. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Certifi over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-37920CRITICAL Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023 | Jul 25, 2023 | 9.8 | 30 | NO | NO |
CVE-2024-39689HIGH Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 | Jul 5, 2024 | 7.5 | 24 | NO | NO |
CVE-2022-23491HIGH Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes ro | Dec 7, 2022 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Certifi.
Media articles that mention a CVE ID that affects a product developed by Certifi — matched by CVE ID, not by vendor name.