boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-297

Weakness type CWE-297 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
18160

Monthly trend

▂▁▁▂▁▁▁▁▁▁▃▆█▆

2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 4 · 2026-07 6 · 2026-08 4

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-438697.347.6Apache Thrift: TSSLTransportFactory.java hostname verification
CVE-2026-659427.544.4Apache Ranger: Clients accept TLS certificates issued for other hostnames
CVE-2026-481458.236.5Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass
CVE-2026-481449.135.0Apache Thrift: c_glib TLS Client Missing Hostname Verification
CVE-2026-427907.626.9nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verif…
CVE-2026-660535.923.2Apache Thrift: Python TSSLSocket Hostname Matcher Import
CVE-2026-596389.320.1JSSE hostname verifier CN-fallback enabled by default despite documented opt-in
CVE-2026-580406.319.6
CVE-2026-542752.718.6AIOHTTP: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
CVE-2026-355638.88.1Apache Directory LDAP API: LDAP client implementation does not verify if the server cer…
CVE-2026-159259.27.5Improper TLS Hostname Verification in Snowflake Connector for Python
CVE-2026-443937.47.0
CVE-2026-152437.46.7Improper Validation of Certificate in CAS Client
CVE-2026-127303.86.3Improper Validation of Certificate with Host Mismatch in IBM Business Automation Workfl…
CVE-2026-494579.14.6QUIC has Broken TLS verification
CVE-2026-121625.54.5
CVE-2025-252536.81.2
CVE-2025-42954.61.2Host Header Injection in HotelRunner's B2B

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache6
aio-libs1
apereo1
benoitc1
devolutions1
erlang1
fortinet1
hotelrunner1
ibm1
legion of the bouncy castle1
nodejs1
snowflake1