A certificate expiration is not validated or is incorrectly validated.
Check for expired certificates and provide the user with adequate information about the nature of the problem and how to proceed.
If certificate pinning is being used, ensure that all relevant properties of the certificate are fully validated before the certificate is pinned, including the expiration.
The data read from the system vouched for by the expired certificate may be flawed due to malicious spoofing.
Trust may be assigned to certificates that have been abandoned due to age.
CVE-2025-4384product does not verify that a certificate has expired
CVE-2007-3564web library product does not verify that a certificate has expired
CVE-2007-6746IRC product does not check the expiration date of the X.509 certificate
CVE-2007-6746library for SSL and TLS does not check the activation or expiration dates of CA certificates