CWE-322
CVEs classified under CWE-322, newest first.
7 CVEsRSS
CVE-2026-78807High· 7.1wpa_supplicant: wpa_supplicant: Security bypass via missing PMKSA validation (CVE-2026-78807)
A flaw was found in wpa_supplicant. A local attacker can exploit missing validation in the driver-based PMKSA (Pairwise Master Key Security Association) selection path to bypass proper network context and AKMP (Authentication Key Managemen…
CVE-2026-18654Medium· 6.8AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
CVE-2026-58065High· 8.1The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification
The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server…
CVE-2026-11745High· 8.8PoCA vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-t…
A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-t…
CVE-2025-13914High· 8.7A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an att…
A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an att…
CVE-2026-1709Critical· 9.4A flaw was found in Keylime
A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network ac…
CVE-2025-10966Medium· 4.3curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.
curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.