Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-322
Weakness type CWE-322 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 7 | 6 | 0 |
Monthly trend
▅▁▁▁▁▁▅▅▅▅█▁
2025-11 1 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 1 · 2026-07 1 · 2026-08 1 · 2026-09 2 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-45361 | 8.1 | 55.2 | — | Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHH… |
| CVE-2026-58065 | 8.1 | 52.9 | — | Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, di… |
| CVE-2026-89422 | 9.3 | 49.1 | — | TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_… |
| CVE-2025-10966 | 4.3 | 31.8 | — | missing SFTP host verification with wolfSSH |
| CVE-2026-18654 | 6.9 | 19.7 | — | Disabled SSH host key verification in Amazon AWS CLI EMR helper commands |
| CVE-2026-77703 | 5.9 | 13.6 | — | SSH Host Key Verification Bypass in HAVELSAN's Liman Render Engine |
| CVE-2026-11745 | 8.8 | 11.2 | — | — |