Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-322 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 4 | 4 | 0 |
████
2026-05 1 · 2026-06 1 · 2026-07 1 · 2026-08 1
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-45361 | 8.1 | 45.6 | — | Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHH… |
| CVE-2026-58065 | 8.1 | 39.4 | — | Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, di… |
| CVE-2026-18654 | 6.9 | 21.6 | — | Disabled SSH host key verification in Amazon AWS CLI EMR helper commands |
| CVE-2026-11745 | 8.8 | 12.7 | — | — |