What is CWE-297?
The product communicates with a host that provides a certificate, but the product does not properly ensure that the certificate is actually associated with that host.
Even if a certificate is well-formed, signed, and follows the chain of trust, it may simply be a valid certificate for a different site than the site that the product is interacting with. In order to ensure data integrity, the certificate must be valid, and it must pertain to the site that is being accessed. Even if the product attempts to check the hostname, it is still possible to incorrectly check the hostname. For example, attackers could create a certificate with a name that begins with a trusted name followed by a NUL byte, which could cause some string-based comparisons to only examine the portion that contains the trusted name.
CWE-297 is a variant-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of High. Applicable platforms: Not Language-Specific; Not Technology-Specific; Mobile; Web Based.
Source: MITRE CWE (CWE-297 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Access Control — Gain Privileges or Assume Identity. The data read from the system vouched for by the certificate may not be from the expected system.
- Authentication, Other — Other. Trust afforded to the system in question - based on the malicious certificate - may allow for spoofing or redirection attacks.
- Access Control, Other — Gain Privileges or Assume Identity, Other. If the certificate's host-specific data is not properly checked - such as the Common Name (CN) in the Subject or the Subject Alternative Name (SAN) extension of an X.509 certificate - it may be possible for a redirection or spoofing attack to allow a malicious host with a valid certificate to provide data, impersonating a trusted host.
Source: MITRE CWE, common consequences.
How CWE-297 is exploited in the wild
Threadlinqs maps 3 CVEs to CWE-297, published between 2025-10-14 and 2026-09-25. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 3 medium. The highest EPSS score in the set is 0.2% (CVE-2026-58040), the modelled probability of exploitation in the next 30 days. 5 tracked threats reference CWE-297 directly or through a CVE it covers; the most recent is “Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage (CVE-2026-91765, CVE-2026-91768, CVE-2026-6103 and 8 Others) — GovCERT.HK A26-09-40” (2026-09-25). Affected products concentrate in Fortinet (1), PHP Group (1), nodejs (1).
Vulnerabilities (CVEs)
All 3 CVEs mapped to CWE-297, CISA KEV first, then by CVSS score.
- CVE-2025-25253 — CVSS 6.8 medium · EPSS 0.1% · published 2025-10-14
- CVE-2026-58040 — CVSS 6.3 medium · EPSS 0.2% · published 2026-07-30
- CVE-2026-91769 — CVSS 4.3 medium · published 2026-09-25
Affected vendors
Threat activity
5 tracked threats cite CWE-297:
- Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage (CVE-2026-91765, CVE-2026-91768, CVE-2026-6103 and 8 Others) — GovCERT.HK A26-09-40MEDIUM
- Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)CRITICAL
- Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1, v26.5.1 (HTTP/2 DoS, Permission Model Bypass, TLS/mTLS Issues)HIGH
- Node.js June 2026 Security Release — 12 Vulnerabilities Across 22.x/24.x/26.x Including Two High-Severity TLS Authentication Bypass and WebCrypto DoS Flaws (CVE-2026-48618, CVE-2026-48933)HIGH
- Cisco Webex Services Critical Improper Certificate Validation Flaw (CVE-2026-20184) Enables Man-in-the-Middle Against Cloud Meeting TrafficCRITICAL
Mitigations
- Architecture and Design: Fully check the hostname of the certificate and provide the user with adequate information about the nature of the problem and how to proceed.
- Implementation: If certificate pinning is being used, ensure that all relevant properties of the certificate are fully validated before the certificate is pinned, including the hostname.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
- Dynamic Analysis with Manual Results Interpretation: Set up an untrusted endpoint (e.g. a server) with which the product will connect. Create a test certificate that uses an invalid hostname but is signed by a trusted CA and provide this certificate from the untrusted endpoint. If the product performs any operations instead of disconnecting and reporting an error, then this indicates that the hostname is not being checked and the test certificate has been accepted.
- Black Box: When Certificate Pinning is being used in a mobile application, consider using a tool such as Spinner [REF-955]. This methodology might be extensible to other technologies.
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.