CWE-297Variant

Improper Validation of Certificate with Host Mismatch

Incomplete in the CWE catalog · 57 CVEs mapped

57
CVEs mapped
6.8
Median CVSS
What it is

The product communicates with a host that provides a certificate, but the product does not properly ensure that the certificate is actually associated with that host.

Recent examples
5.3cvss
CVE-2026-9744

CVE-2026-9744 - MEDIUM Severity Vulnerability

IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.

MEDIUMno explanation yet
0%
epss
6.8cvss
CVE-2026-59272

CVE-2026-59272 - MEDIUM Severity Vulnerability

Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier

MEDIUMno explanation yet
0%
epss
7.5cvss
CVE-2026-62243

CVE-2026-62243 - HIGH Severity Vulnerability

Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsafe-based trust-manager wrapping is unavailable (Java 25+). In this configuration the OpenSSL client does not perform hostname verification, allowing a man-in-the-middle attacker to present a certificate issued for a different hostname that is accepted without validation. Fixed in 4.2.17.Final and 4.1.137.Final.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-297
Abstraction
Variant
Structure
Simple
Status
Incomplete
References (6)