Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.1
CVE-2026-71290
Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effe…
Httpclient
No fix yet
CRITICAL 10.0
CVE-2026-58162
The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI.
This issue affects Apache Traffic Server:…
Traffic Server
9.2.15 / 10.1.4+
HIGH 7.3
CVE-2026-56624
Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH.
Server…
Mina Sshd
2.19.0+
MEDIUM 5.9
CVE-2026-49267
Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections without verifying the remote ce…
Airflow
3.2.2+
HIGH 7.3
CVE-2026-43869
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are re…
Thrift
0.23.0+
MEDIUM 5.9
CVE-2026-41016
Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performe…
Airflow
3.0.0+
HIGH 7.4
CVE-2026-41603
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are re…
Thrift
0.23.0+
MEDIUM 5.9
CVE-2026-34477
The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when ena…
Log4j
2.25.4+
HIGH 7.4
CVE-2026-24281
Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control…
Zookeeper
3.8.6 / 3.9.5+
HIGH 7.5
CVE-2026-24734
Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat.
When using an OCSP responder, Tomcat Native (and Tomcat's FFM port o…
Tomcat
1.3.5 / 2.0.12+
CRITICAL 9.1
CVE-2025-66614
Improper Input Validation vulnerability.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.…
Tomcat
9.0.113 / 10.1.50+
HIGH 7.5
CVE-2025-27820
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered b…
Httpclient
5.4.3+
CRITICAL 9.1
CVE-2024-25141
When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpecte…
Apache Airflow Providers Mongo
4.0.0+
HIGH 7.3
CVE-2023-49250
Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connectio…
Dolphinscheduler
3.2.1+
MEDIUM 5.9
CVE-2023-41180
Incorrect certificate validation in InvokeHTTP on Apache NiFi MiNiFi C++ versions 0.13 to 0.14 allows an intermediary to present a forged certificate…
Nifi Minifi C\+\+
after 0.14.0
MEDIUM 5.9
CVE-2023-39441
Apache Airflow SMTP Provider before 1.3.0, Apache Airflow IMAP Provider before 3.3.0, and Apache Airflow before 2.7.0 are affected by the Validation …
Airflow
1.3.0 / 2.7.0+
MEDIUM 5.9
CVE-2022-32531
The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verificati…
Bookkeeper
4.14.6+
HIGH 8.1
CVE-2022-33684
The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Credential Flow, even when tlsAllo…
Pulsar
2.7.5 / 2.8.4+
MEDIUM 5.9
CVE-2022-33681
Delayed TLS hostname verification in the Pulsar Java Client and the Pulsar Proxy make each client vulnerable to a man in the middle attack. Connectio…
Pulsar
2.7.5 / 2.8.4+
MEDIUM 5.9
CVE-2022-33682
TLS hostname verification cannot be enabled in the Pulsar Broker's Java Client, the Pulsar Broker's Java Admin Client, the Pulsar WebSocket Proxy's J…
Pulsar
2.7.5 / 2.8.4+
MEDIUM 5.9
CVE-2022-33683
Apache Pulsar Brokers and Proxies create an internal Pulsar Admin Client that does not verify peer TLS certificates, even when tlsAllowInsecureConnec…
Pulsar
2.7.5 / 2.8.4+
HIGH 7.4
CVE-2021-44549
Apache Sling Commons Messaging Mail provides a simple layer on top of JavaMail/Jakarta Mail for OSGi to send mails via SMTPS. To reduce the risk of "…
Sling Commons Messaging Mail
Mitigation only
MEDIUM 5.9
CVE-2020-13955
HttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections making clients vulnerable to man-in-the-middle atta…
Calcite
1.26+
CRITICAL 9.8
CVE-2020-1952
An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, c…
Iotdb
after 0.9.1
CRITICAL 9.1
CVE-2019-17560
The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to interc…
Netbeans
after 11.2
HIGH 7.4
CVE-2019-10091
When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the c…
Geode
Mitigation only
HIGH 7.5
CVE-2020-1929
The Apache Beam MongoDB connector in versions 2.10.0 to 2.16.0 has an option to disable SSL trust verification. However this configuration is not res…
Beam
after 2.16.0
HIGH 7.5
CVE-2018-20245
The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and contained improper checking of e…
Airflow
1.10.1+
HIGH 7.5
CVE-2018-1320EPSS 8%
Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.…
Thrift
11.2.0.3.23 / 12.2.0.1.19+
HIGH 7.4
CVE-2018-17187
The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.ssl(...)' methods. Unless a ve…
Qpid Proton J
after 0.29.0