VulnSea

CWE-322

CVEs classified under CWE-322, newest first.

7 CVEsRSS

CVE-2026-78807High· 7.1
1w ago

wpa_supplicant: wpa_supplicant: Security bypass via missing PMKSA validation (CVE-2026-78807)

A flaw was found in wpa_supplicant. A local attacker can exploit missing validation in the driver-based PMKSA (Pairwise Master Key Security Association) selection path to bypass proper network context and AKMP (Authentication Key Managemen…

TwilightRed Hat · Red Hat Enterprise Linux 6EPSS 0.08%via CSAF
CVE-2026-18654Medium· 6.8
1mo ago

AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands

AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands

Sunlitawscli · awscliEPSS 0.29%via OSV
CVE-2026-58065High· 8.1
2mo ago

The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification

The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server…

Twilightapache · apache-airflow-providers-gitEPSS 0.74%via NVD
CVE-2026-11745High· 8.8PoC
3mo ago

A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-t…

A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-t…

MidnightLY Corporation · Central DogmaEPSS 0.22%via NVD
CVE-2025-13914High· 8.7
5mo ago

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an att…

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an att…

Twilightjuniper · apstraEPSS 0.30%via NVD
CVE-2026-1709Critical· 9.4
7mo ago

A flaw was found in Keylime

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network ac…

Midnightkeylime · keylimeEPSS 5.5%via NVD
CVE-2025-10966Medium· 4.3
10mo ago

curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.

curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.

Sunlithaxx · curlEPSS 0.40%via NVD
CWE-322 vulnerabilities (CVEs) · VulnSea