boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-297

Weakness type CWE-297 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
40370

Monthly trend

▂▁▁▂▁▁▂▁▁▂▁▂▁▂▃▆▅█▂

2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 2 · 2026-06 4 · 2026-07 8 · 2026-08 7 · 2026-09 12 · 2026-10 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-438697.355.4—Apache Thrift: TSSLTransportFactory.java hostname verification
CVE-2026-659427.546.3—Apache Ranger: Clients accept TLS certificates issued for other hostnames
CVE-2025-150795.343.3—libssh global known_hosts override
CVE-2026-95477.441.2—SSH improper host validation
CVE-2026-542752.738.5—AIOHTTP: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
CVE-2026-427907.638.4—nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verif…
CVE-2025-35018.237.5—Org.keycloak.protocol.services: keycloak hostname verification
CVE-2026-481458.233.8—Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass
CVE-2026-195537.632.0—SSLContext.wrap_bio() missing validation of server_hostname parameter
CVE-2026-481449.132.0—Apache Thrift: c_glib TLS Client Missing Hostname Verification
CVE-2026-120647.531.8—proto-default skips SSH verification
CVE-2026-929439.229.8—Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python
CVE-2026-596389.325.8—JSSE hostname verifier CN-fallback enabled by default despite documented opt-in
CVE-2026-841979.225.6——
CVE-2025-590605.324.7—Apache Ranger: Hostname verification bypass in NiFiRegistryClient
CVE-2026-599697.523.8—Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode
CVE-2026-660535.919.8—Apache Thrift: Python TSSLSocket Hostname Matcher Import
CVE-2026-633749.319.5—AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
CVE-2026-159259.219.4—Improper TLS Hostname Verification in Snowflake Connector for Python
CVE-2026-443937.418.7——

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache9
curl3
dell2
fortinet2
ibm2
agronholm1
aio-libs1
apereo1
aws1
benoitc1
devolutions1
eclipse foundation1
erlang1
hotelrunner1
joyland1