VYPR

CWE-297

Improper Validation of Certificate with Host Mismatch

VariantIncompleteLikelihood: High

Description

The product communicates with a host that provides a certificate, but the product does not properly ensure that the certificate is actually associated with that host.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (90)

page 4 of 5
  • CVE-2026-59638MedAug 3, 2026
    risk 0.35cvss 6.5epss 0.00

    In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24…

  • CVE-2024-32868MedApr 26, 2024
    risk 0.35cvss 6.5epss 0.00

    ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email. While ZITADEL already gives administrators the option to define a `Lockout Policy` with a maximum amount of failed password check attempts, there…

  • CVE-2024-2466MedMar 27, 2024
    risk 0.35cvss 6.5epss 0.01

    libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely…

  • CVE-2022-22305MedSep 1, 2023
    risk 0.35cvss 5.4epss 0.00

    An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker…

  • CVE-2020-1758MedMay 15, 2020
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.

  • CVE-2026-9744MedSep 3, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.

  • CVE-2025-59060MedMar 3, 2026
    risk 0.34cvss 5.3epss 0.00

    Hostname verification bypass issue in Apache Ranger NiFiRegistryClient is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.

  • CVE-2023-24568MedMay 30, 2023
    risk 0.33cvss 5.0epss 0.00

    Dell NetWorker, contains an Improper Validation of Certificate with Host Mismatch vulnerability in Rabbitmq port which could disallow replacing CA signed certificates.

  • CVE-2026-79943MedSep 7, 2026
    risk 0.31cvss 4.8epss 0.00

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Validation of Certificate with Host Mismatch vulnerability. An unauthenticated attacker with remote access could potentially exploit this…

  • CVE-2026-66053MedJul 27, 2026
    risk 0.31cvss 5.9epss 0.00

    Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603

  • CVE-2026-34477MedApr 10, 2026
    risk 0.31cvss 5.9epss 0.00

    The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName …

  • CVE-2024-54019MedJun 10, 2025
    risk 0.31cvss 4.8epss 0.00

    A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 all versions allow an unauthorized attacker to redirect VPN connections via DNS spoofing or another form of redirection.

  • CVE-2024-8285MedAug 30, 2024
    risk 0.31cvss 5.9epss 0.00

    A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails to properly verify the server's hostname, resulting in an insecure connection. For a successful attack to be performed, the…

  • CVE-2025-4295MedJul 22, 2025
    risk 0.30cvss 4.6epss 0.00

    Improper Validation of Certificate with Host Mismatch vulnerability in HotelRunner B2B allows HTTP Response Splitting. This issue affects B2B: before 04.06.2025.

  • CVE-2025-15079MedJan 8, 2026
    risk 0.27cvss 5.3epss 0.01

    When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file.

  • CVE-2025-42921MedApr 17, 2025
    risk 0.27cvss 4.2epss 0.00

    In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin

  • CVE-2018-19946MedSep 11, 2020
    risk 0.27cvss 4.2epss 0.00

    The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. QNAP has already…

  • CVE-2026-12730LowAug 5, 2026
    risk 0.25cvss 3.8epss 0.00

    IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the…

  • CVE-2025-49015MedJun 18, 2025
    risk 0.25cvss 4.9epss 0.00

    The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of hostnames due to a configuration option that was incorrectly enabled by default.

  • CVE-2025-68161MedDec 18, 2025
    risk 0.24cvss 4.8epss 0.01

    The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName …