CWE-297: Improper Validation of Certificate with Host Mismatch
The product communicates with a host that provides a certificate, but the product does not properly ensure that the certificate is actually associated with that host.
59 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-59638 — JSSE hostname verifier CN-fallback enabled by default despite documented opt-in
- CVE-2026-84197 — In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from
- CVE-2026-15925 — Improper TLS Hostname Verification in Snowflake Connector for Python
- CVE-2026-26214 — Xiaomi Galaxy FDS Android SDK <= 3.0.8 TLS Hostname Verification Disabled Enables MITM
- CVE-2026-49457 — QUIC has Broken TLS verification
- CVE-2026-48144 — Apache Thrift: c_glib TLS Client Missing Hostname Verification
- CVE-2026-35563 — Apache Directory LDAP API: LDAP client implementation does not verify if the server certificate matches the intended LDAP hostname
- CVE-2026-62243 — Netty 4.2.0 through 4.2.16 TLS Hostname Verification Bypass
- CVE-2026-41603 — Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift:
- CVE-2026-48145 — Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass
- CVE-2024-49782 — IBM OpenPages improper certificate validation
- CVE-2024-32868 — ZITADEL's Improper Lockout Mechanism Leads to MFA Bypass
- CVE-2026-42790 — nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification
- CVE-2026-65942 — Apache Ranger: Clients accept TLS certificates issued for other hostnames
- CVE-2026-44467 — Claude Desktop: SSH Host Key Verification Bypass Allows Man-in-the-Middle Attack on Remote Sessions
- CVE-2026-15243 — Improper Validation of Certificate in CAS Client
- CVE-2026-84393 — A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProx
- CVE-2024-12925 — Host Header Injection in Akinsoft's QR Menu
- CVE-2024-38324 — IBM Storage Defender improper certificate validation
- CVE-2026-79636 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
Recently published
- CVE-2026-79636 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-84197 — In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from
- CVE-2026-84393 — A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProx
- CVE-2026-79943 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-9744 — Vulnerabilities exists in IBM Netezza Software
- CVE-2026-62243 — Netty 4.2.0 through 4.2.16 TLS Hostname Verification Bypass
- CVE-2026-53583 — libgit2: Inverted IP SubjectAltName Comparison in OpenSSL Backend
- CVE-2026-49457 — QUIC has Broken TLS verification
- CVE-2026-65942 — Apache Ranger: Clients accept TLS certificates issued for other hostnames
- CVE-2026-12730 — Improper Validation of Certificate with Host Mismatch in IBM Business Automation Workflow containers
- CVE-2026-59638 — JSSE hostname verifier CN-fallback enabled by default despite documented opt-in
- CVE-2026-66053 — Apache Thrift: Python TSSLSocket Hostname Matcher Import
- CVE-2026-48145 — Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass
- CVE-2026-48144 — Apache Thrift: c_glib TLS Client Missing Hostname Verification
- CVE-2026-15243 — Improper Validation of Certificate in CAS Client
- CVE-2026-15925 — Improper TLS Hostname Verification in Snowflake Connector for Python
- CVE-2026-54275 — AIOHTTP: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
- CVE-2026-35563 — Apache Directory LDAP API: LDAP client implementation does not verify if the server certificate matches the intended LDAP hostname
- CVE-2026-42790 — nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification
- CVE-2026-44467 — Claude Desktop: SSH Host Key Verification Bypass Allows Man-in-the-Middle Attack on Remote Sessions