Skip to main content

CWE archive

CWE-297 CVEs

Programmatic archive

61 CVEs tagged with CWE-2978 Critical, 19 High, 32 Medium, 2 Low, 0 Unrated.

CVE-2026-66053

Published Jul 27, 2026

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to u…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-48145

Published Jul 27, 2026

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgr…

CVSS 8.2 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-48144

Published Jul 27, 2026

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to u…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-15243

Published Jul 24, 2026

Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches the configured allowlist or regex. An attacker with a MITM po…

CVSS 7.4 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-15925

Published Jul 16, 2026

Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostna…

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-54275

Published Jun 22, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is r…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-12162

Published Jun 16, 2026

Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via a…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44393

Published Jun 4, 2026

An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not perform TLS hostname verification when connecting to the mess…

CVSS 7.4 · High
evidence mentions
5
Buzz score
32.4

CVE-2026-35563

Published Jun 1, 2026

It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the intended LDAP hostname. While the underlying code val…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-42790

Published May 27, 2026

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in…

CVSS 7.6 · High
evidence mentions
12
Buzz score
45.6
Vendor/product tagsBeta · best-effort

CVE-2026-44467

Published May 13, 2026

The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. From 1.2581.0 to before 1.4304.0, Claude Desktop's SSH re…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-43869

Published May 5, 2026

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to versio…

CVSS 7.3 · High
evidence mentions
19
Buzz score
49.5
Vendor/product tagsBeta · best-effort

CVE-2026-22747

Published Apr 22, 2026

Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong…

CVSS 6.8 · Medium
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-34477

Published Apr 10, 2026

The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the log4j2.sslVerify…

CVSS 6.3 · Medium
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2025-59060

Published Mar 3, 2026

Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-26214

Published Feb 12, 2026

Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HTTPS is enabled (the default configuration). In GalaxyFDSCli…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
20.4

CVE-2025-15079

Published Jan 8, 2026

When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2025-68637

Published Jan 7, 2026

The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This insecure configuration exposes all REST API communication…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-68161

Published Dec 18, 2025

The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https:…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-25253

Published Oct 14, 2025

An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-46408

Published Sep 15, 2025

An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_HttpService.getNewHttpClient in AVTECH EagleEyes 2.0.0. The me…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-12925

Published Sep 1, 2025

Improper Validation of Certificate with Host Mismatch vulnerability in Akınsoft QR Menü allows HTTP Response Splitting. This issue affects QR Menü: from s1.05.05 before v1.05.12.

CVSS 7.3 · High

CVE-2025-4295

Published Jul 22, 2025

Improper Validation of Certificate with Host Mismatch vulnerability in HotelRunner B2B allows HTTP Response Splitting. This issue affects B2B: before 04.06.2025.

CVSS 4.6 · Medium

CVE-2025-49015

Published Jun 18, 2025

The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of h…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54019

Published Jun 10, 2025

A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 all versions allow an unauthorized atta…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 61 CVEsPage 1 of 3