Improper Validation of Certificate with Host Mismatch

CWE-297 · 5 records · 3 with a public proof-of-concept

Records the NVD classes as Improper Validation of Certificate with Host Mismatch (CWE-297), highest CVSS first.

  1. HIGH 7.5CVE-2026-59969

    Apache ZooKeeper quorum TLS fails to enforce peer hostname verification in FIPS-mode deployments. When sslQuorum=true, zookeeper.fips-mode=true, ssl.quorum.hostnameVerification=true, and ssl.quorum.clientHostnameVerification=true are enabled, the Java SSLSocke…

    zookeeper

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 5.7CVE-2026-91166public PoC

    Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path in warpgate-web-ssh/src/manager.rs handles RCEvent::HostKeyUnknown without the presenting hop identity and instead passes ssh_options.host an…

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 4.3CVE-2026-91769public PoC

    PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once the certificate presents any service identity, so a certific…

    AI risk analysis on Exploit-DB.ai →

  4. LOW 3.8CVE-2026-12730

    IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostn…

    business automation workflow

    AI risk analysis on Exploit-DB.ai →

  5. UNSCOREDCVE-2026-63374public PoC

    AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard library converts them with IDN…

    AI risk analysis on Exploit-DB.ai →