CVE-2025-59060
Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.33%
- CWE
- CWE-297
- Published
- 2026-03-03
- Last modified
- 2026-08-24
Affected products
- Apache Software Foundation Apache Ranger
Weakness type
Related vulnerabilities
- CVE-2020-11050 — Improper Validation of Certificate with Host Mismatch in Java-WebSocket
- CVE-2021-21385 — Disabled hostname verification and accepting self-signed certificates
- CVE-2025-3501 — Org.keycloak.protocol.services: keycloak hostname verification
- CVE-2018-10936 — A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check t
- CVE-2022-32153 — Splunk Enterprise lacked TLS host name validation
- CVE-2026-59638 — JSSE hostname verifier CN-fallback enabled by default despite documented opt-in
- CVE-2026-84197 — In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from
- CVE-2026-15925 — Improper TLS Hostname Verification in Snowflake Connector for Python