Cryptographic failures
Comment: Looks like sources are mostly company websites SomeoneDreaming (talk) 22:22, 19 July 2026 (UTC)
Cryptographic failures are web application security vulnerabilities caused by the improper use of cryptography, which can expose sensitive information.[1][2] The term was introduced in the OWASP Top 10 (2021), replacing Sensitive Data Exposure to emphasize failures in the implementation of cryptographic controls.[3]
Common causes
Common causes of cryptographic failures include:[4][5]
- Use of weak or deprecated cryptographic algorithms.
- Failure to encrypt sensitive data at rest or in transit.
- Improper certificate validation.
- Insecure storage or management of cryptographic keys.
- Predictable or weak random number generation.
- Use of outdated TLS or SSL protocols.
See also
- Cryptography
- Transport Layer Security
- Public-key cryptography
- Data encryption
- Web application security
References
- ↑ SitePoint. "Radware Page". radware.com. Retrieved 2026-07-19.
- ↑ "Cryptographic Failures: What They Are, Examples & How to Prevent Them". www.softwaresecured.com. Retrieved 2026-07-19.
- ↑ "A02 Cryptographic Failures - OWASP Top 10:2021". owasp.org. Retrieved 2026-07-19.
- ↑ "Cryptographic Failures: Impact, Root Causes & Examples | TraceX Labs". TraceX Labs. Retrieved 2026-07-19.
- ↑ Codacy. "Cryptographic Failures: A Complete Guide". blog.codacy.com. Retrieved 2026-07-19.
Category:Web security exploits Category:Hacking (computer security)
| This computer security article is a stub. You can help EverybodyWiki by expanding it. |
This article "Cryptographic failures" is from Wikipedia. The list of its authors can be seen in its historical and/or the page Edithistory:Cryptographic failures. Articles copied from Draft Namespace on Wikipedia could be seen on the Draft Namespace of Wikipedia and not main one.
