The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affect
erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the serve
It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server certificate matches
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects A
TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to v
Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable
Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HT
An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not pe
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift:
Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509
The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is expose
In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in.
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing
An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across ident
The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostna
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affect
Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an
When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenl
Hostname verification bypass issue in Apache Ranger NiFiRegistryClient is reported in Apache Ranger versions <= 2.7.0.
IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 throug
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed
Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches th
Frequently Asked Questions
What is CWE-297?
CWE-297 (CWE-297) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-297?
There are 26 CVE records associated with CWE-297 in our database. Of these, 3 are critical severity, 9 are high severity, and 11 are medium severity.
How can I protect against CWE-297 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-297 using AI-powered security agents.
Detect CWE-297 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-297 vulnerabilities across your infrastructure.
Get Started