VYPR

CWE-297

Improper Validation of Certificate with Host Mismatch

VariantIncompleteLikelihood: High

Description

The product communicates with a host that provides a certificate, but the product does not properly ensure that the certificate is actually associated with that host.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (76)

page 1 of 4
  • CVE-2025-46408CriSep 15, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_HttpService.getNewHttpClient in AVTECH EagleEyes 2.0.0. The methods set ALLOW_ALL_HOSTNAME_VERIFIER, bypassing domain validation.

  • CVE-2026-49457CriAug 14, 2026
    risk 0.59cvss 9.1epss

    erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared…

  • CVE-2021-33695CriSep 15, 2021
    risk 0.59cvss 9.1epss 0.01

    Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate.

  • CVE-2020-11050CriMay 7, 2020
    risk 0.59cvss 9.0epss 0.01

    In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0.

  • CVE-2026-59638CriAug 3, 2026
    risk 0.53cvss epss 0.00

    In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24…

  • CVE-2025-2190HigMar 11, 2025
    risk 0.53cvss 8.1epss 0.00

    The mobile application (com.transsnet.store) has a man-in-the-middle attack vulnerability, which may lead to code injection risks.

  • CVE-2022-41244HigSep 21, 2022
    risk 0.53cvss 8.1epss 0.01

    Jenkins View26 Test-Reporting Plugin 1.0.7 and earlier does not perform hostname validation when connecting to the configured View26 server that could be abused using a man-in-the-middle attack to intercept these connections.

  • CVE-2022-41243HigSep 21, 2022
    risk 0.53cvss 8.1epss 0.01

    Jenkins SmallTest Plugin 1.0.4 and earlier does not perform hostname validation when connecting to the configured View26 server that could be abused using a man-in-the-middle attack to intercept these connections.

  • CVE-2022-32153HigJun 15, 2022
    risk 0.53cvss 8.1epss 0.01

    Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certificates during Splunk-to-Splunk communications by default. Splunk peer communications configured properly with valid certificates…

  • CVE-2018-10936HigAug 30, 2018
    risk 0.53cvss 8.1epss 0.03

    A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a…

  • CVE-2026-48144CriJul 27, 2026
    risk 0.52cvss 9.1epss 0.00

    Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

  • CVE-2025-68637CriJan 7, 2026
    risk 0.52cvss 9.1epss 0.00

    The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This insecure configuration exposes all REST API communication between the Uniffle CLI/client and the Uniffle Coordinator service to potential Man-in-the-Middle…

  • CVE-2026-65942HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.00

    TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

  • CVE-2025-25253HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.00

    An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions and FortiOS version 7.6.2 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions…

  • CVE-2024-41264HigAug 1, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.

  • CVE-2024-34447HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) 2.73.6) and before BC FIPS TLS Java 1.0.19. When endpoint identification is enabled in the BCJSSE and an SSL socket is created without an…

  • CVE-2023-5909HigNov 30, 2023
    risk 0.49cvss 7.5epss 0.00

    KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.

  • CVE-2026-44393HigJun 4, 2026
    risk 0.48cvss 7.4epss 0.00

    An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not perform TLS hostname verification when connecting to the message broker. When ssl_ca_file is configured, the driver enables certificate chain validation but does…

  • CVE-2026-35563HigJun 1, 2026
    risk 0.48cvss 8.5epss 0.00

    It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the intended LDAP hostname. While the underlying code validates the certificate chain against a trusted authority, the absence of endpoint identification …

  • CVE-2026-26214HigFeb 12, 2026
    risk 0.48cvss 7.4epss 0.00

    Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HTTPS is enabled (the default configuration). In GalaxyFDSClientImpl.createHttpClient(), the SDK configures Apache HttpClient with…