Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-297
Weakness type CWE-297 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 40 | 37 | 0 |
Monthly trend
▂▁▁▂▁▁▂▁▁▂▁▂▁▂▃▆▅█▂
2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 2 · 2026-06 4 · 2026-07 8 · 2026-08 7 · 2026-09 12 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-43869 | 7.3 | 55.4 | — | Apache Thrift: TSSLTransportFactory.java hostname verification |
| CVE-2026-65942 | 7.5 | 46.3 | — | Apache Ranger: Clients accept TLS certificates issued for other hostnames |
| CVE-2025-15079 | 5.3 | 43.3 | — | libssh global known_hosts override |
| CVE-2026-9547 | 7.4 | 41.2 | — | SSH improper host validation |
| CVE-2026-54275 | 2.7 | 38.5 | — | AIOHTTP: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections |
| CVE-2026-42790 | 7.6 | 38.4 | — | nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verif… |
| CVE-2025-3501 | 8.2 | 37.5 | — | Org.keycloak.protocol.services: keycloak hostname verification |
| CVE-2026-48145 | 8.2 | 33.8 | — | Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass |
| CVE-2026-19553 | 7.6 | 32.0 | — | SSLContext.wrap_bio() missing validation of server_hostname parameter |
| CVE-2026-48144 | 9.1 | 32.0 | — | Apache Thrift: c_glib TLS Client Missing Hostname Verification |
| CVE-2026-12064 | 7.5 | 31.8 | — | proto-default skips SSH verification |
| CVE-2026-92943 | 9.2 | 29.8 | — | Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python |
| CVE-2026-59638 | 9.3 | 25.8 | — | JSSE hostname verifier CN-fallback enabled by default despite documented opt-in |
| CVE-2026-84197 | 9.2 | 25.6 | — | — |
| CVE-2025-59060 | 5.3 | 24.7 | — | Apache Ranger: Hostname verification bypass in NiFiRegistryClient |
| CVE-2026-59969 | 7.5 | 23.8 | — | Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode |
| CVE-2026-66053 | 5.9 | 19.8 | — | Apache Thrift: Python TSSLSocket Hostname Matcher Import |
| CVE-2026-63374 | 9.3 | 19.5 | — | AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing |
| CVE-2026-15925 | 9.2 | 19.4 | — | Improper TLS Hostname Verification in Snowflake Connector for Python |
| CVE-2026-44393 | 7.4 | 18.7 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 9 |
| curl | 3 |
| dell | 2 |
| fortinet | 2 |
| ibm | 2 |
| agronholm | 1 |
| aio-libs | 1 |
| apereo | 1 |
| aws | 1 |
| benoitc | 1 |
| devolutions | 1 |
| eclipse foundation | 1 |
| erlang | 1 |
| hotelrunner | 1 |
| joyland | 1 |