Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-297 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 18 | 16 | 0 |
▂▁▁▂▁▁▁▁▁▁▃▆█▆
2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 4 · 2026-07 6 · 2026-08 4
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-43869 | 7.3 | 47.6 | — | Apache Thrift: TSSLTransportFactory.java hostname verification |
| CVE-2026-65942 | 7.5 | 44.4 | — | Apache Ranger: Clients accept TLS certificates issued for other hostnames |
| CVE-2026-48145 | 8.2 | 36.5 | — | Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass |
| CVE-2026-48144 | 9.1 | 35.0 | — | Apache Thrift: c_glib TLS Client Missing Hostname Verification |
| CVE-2026-42790 | 7.6 | 26.9 | — | nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verif… |
| CVE-2026-66053 | 5.9 | 23.2 | — | Apache Thrift: Python TSSLSocket Hostname Matcher Import |
| CVE-2026-59638 | 9.3 | 20.1 | — | JSSE hostname verifier CN-fallback enabled by default despite documented opt-in |
| CVE-2026-58040 | 6.3 | 19.6 | — | — |
| CVE-2026-54275 | 2.7 | 18.6 | — | AIOHTTP: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections |
| CVE-2026-35563 | 8.8 | 8.1 | — | Apache Directory LDAP API: LDAP client implementation does not verify if the server cer… |
| CVE-2026-15925 | 9.2 | 7.5 | — | Improper TLS Hostname Verification in Snowflake Connector for Python |
| CVE-2026-44393 | 7.4 | 7.0 | — | — |
| CVE-2026-15243 | 7.4 | 6.7 | — | Improper Validation of Certificate in CAS Client |
| CVE-2026-12730 | 3.8 | 6.3 | — | Improper Validation of Certificate with Host Mismatch in IBM Business Automation Workfl… |
| CVE-2026-49457 | 9.1 | 4.6 | — | QUIC has Broken TLS verification |
| CVE-2026-12162 | 5.5 | 4.5 | — | — |
| CVE-2025-25253 | 6.8 | 1.2 | — | — |
| CVE-2025-4295 | 4.6 | 1.2 | — | Host Header Injection in HotelRunner's B2B |
| Vendor | CVEs |
|---|---|
| apache | 6 |
| aio-libs | 1 |
| apereo | 1 |
| benoitc | 1 |
| devolutions | 1 |
| erlang | 1 |
| fortinet | 1 |
| hotelrunner | 1 |
| ibm | 1 |
| legion of the bouncy castle | 1 |
| nodejs | 1 |
| snowflake | 1 |