← Browse

Apache Software Foundation

261 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-47359 N/A Apache Cloudstack — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Ap… 2026-08-21 CVE-2026-50112 HIGH 8.8 Apache Cloudstack — SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attac… 2026-08-21 CVE-2026-50222 N/A Apache Cloudstack — Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Clou… 2026-08-21 CVE-2026-59085 N/A Apache Cloudstack — Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhoo… 2026-08-21 CVE-2026-59654 MEDIUM 6.8 Apache Cloudstack — Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global config… 2026-08-21 CVE-2026-59655 N/A Apache Cloudstack — Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authenti… 2026-08-21 CVE-2026-59657 N/A Apache Cloudstack — Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the dat… 2026-08-21 CVE-2026-59780 N/A Apache Cloudstack — Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentic… 2026-08-21 CVE-2026-59799 N/A Apache Cloudstack — Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing b… 2026-08-21 CVE-2026-61397 N/A Apache Cloudstack — Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authent… 2026-08-21 CVE-2026-61398 N/A Apache Cloudstack — Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Pas… 2026-08-21 CVE-2026-61399 N/A Apache Cloudstack — Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock User Function… 2026-08-21 CVE-2026-61400 HIGH 8.8 Apache Cloudstack — Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Cl… 2026-08-21 CVE-2026-61422 N/A Apache Cloudstack — Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functiona… 2026-08-21 CVE-2026-62440 N/A Apache Cloudstack — Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-t… 2026-08-21 CVE-2026-63046 HIGH 8.8 Apache Inlong — Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InL… 2026-08-21 CVE-2026-65613 N/A Apache Cloudstack — Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webhook module… 2026-08-21 CVE-2026-66721 N/A Apache Cloudstack — Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admi… 2026-08-21 CVE-2026-66722 N/A Apache Cloudstack — Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in … 2026-08-21 CVE-2026-66797 MEDIUM 5.4 Apache Cloudstack — Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disc… 2026-08-21 CVE-2026-68745 N/A Apache Cloudstack — Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platf… 2026-08-21 CVE-2026-63015 MEDIUM 4.3 Apache Inlong — Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons can view te… 2026-08-20 CVE-2026-63016 MEDIUM 5.3 Apache Inlong — Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration… 2026-08-20 CVE-2026-63037 N/A Apache Inlong — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache I… 2026-08-20 CVE-2026-63038 N/A Apache Inlong — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache I… 2026-08-20 CVE-2026-63039 N/A Apache Inlong — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache I… 2026-08-20 CVE-2026-63040 N/A Apache Inlong — Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no a… 2026-08-20 CVE-2026-63042 N/A Apache Inlong — Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authentic… 2026-08-20 CVE-2026-63043 N/A Apache Inlong — Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem. T… 2026-08-20 CVE-2026-63044 MEDIUM 5.4 Apache Inlong — Server-Side Request Forgery (SSRF) vulnerability in Apache InLong.  Any authenticated user (no admin role requ… 2026-08-20 CVE-2026-34884 CRITICAL 9.8 Apache Skywalking Mcp — SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. … 2026-08-18 CVE-2026-73631 MEDIUM 4.3 Apache Struts — Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsi… 2026-08-15 CVE-2026-73632 MEDIUM 4.3 Apache Struts — Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response seri… 2026-08-15 CVE-2026-73634 HIGH 7.5 Apache Struts — Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint coll… 2026-08-15 CVE-2026-73635 HIGH 7.5 Apache Struts — Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is c… 2026-08-15 CVE-2026-73633 HIGH 7.5 Apache Struts — Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is co… 2026-08-14 CVE-2026-66256 HIGH 7.2 Apache Shindig Common — ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue… 2026-08-13 CVE-2026-54183 MEDIUM 4.3 Apache Airflow — Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the U… 2026-08-12 CVE-2026-58076 HIGH 8.8 Apache Airflow — Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class nam… 2026-08-12 CVE-2026-59242 MEDIUM 5.4 Apache Airflow — Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal … 2026-08-12 CVE-2026-59244 MEDIUM 6.5 Apache Airflow — Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered … 2026-08-12 CVE-2026-65017 MEDIUM 6.5 Apache Airflow — Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments.… 2026-08-12 CVE-2026-67260 HIGH 7.3 Apache Airflow — Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swe… 2026-08-12 CVE-2026-67587 HIGH 8.8 Apache Airflow — Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, whic… 2026-08-12 CVE-2026-68076 MEDIUM 5.4 Apache Airflow — Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the w… 2026-08-12 CVE-2026-68868 MEDIUM 6.5 Apache Airflow Google Provider — The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team sco… 2026-08-12 CVE-2026-68968 HIGH 7.5 Apache Airflow — Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backf… 2026-08-12 CVE-2026-68969 MEDIUM 6.5 Apache Airflow — Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they w… 2026-08-12 CVE-2026-68970 MEDIUM 6.5 Apache Airflow — Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets store… 2026-08-12 CVE-2026-68971 MEDIUM 6.5 Apache Airflow — Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom re… 2026-08-12 CVE-2026-73237 MEDIUM 6.1 Apache Allura — XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.10.0 before… 2026-08-12 CVE-2026-73238 MEDIUM 6.1 Apache Allura — XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users a… 2026-08-12 CVE-2026-73239 MEDIUM 6.5 Apache Allura — Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache… 2026-08-12 CVE-2026-73240 CRITICAL 9.8 Apache Allura — Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Al… 2026-08-12 CVE-2026-69223 CRITICAL 9.1 Apache Allura — Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allu… 2026-08-11 CVE-2026-71290 CRITICAL 9.1 Apache Httpcomponents Client — Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerific… 2026-08-11 CVE-2026-28672 CRITICAL 9.8 Apache Ranger — Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ra… 2026-08-10 CVE-2026-32227 CRITICAL 9.8 Apache Ranger — SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to up… 2026-08-10 CVE-2026-40920 CRITICAL 9.8 Apache Ranger — Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended … 2026-08-10 CVE-2026-42537 CRITICAL 9.8 Apache Ranger — Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to ver… 2026-08-10 CVE-2026-44416 CRITICAL 9.8 Apache Ranger — Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <… 2026-08-10 CVE-2026-44630 HIGH 7.5 Apache Iotdb — Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attack… 2026-08-10 CVE-2026-55799 CRITICAL 9.8 Apache Ranger — Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommende… 2026-08-10 CVE-2026-55814 HIGH 7.5 Apache Ranger — Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade t… 2026-08-10 CVE-2026-61899 HIGH 7.5 Apache Tapestry — Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspat… 2026-08-10 CVE-2026-65942 HIGH 7.5 Apache Ranger — TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to up… 2026-08-10 CVE-2026-65945 MEDIUM 6.5 Apache Ranger — Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to vers… 2026-08-10 CVE-2026-65948 HIGH 7.3 Apache Ranger — UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommende… 2026-08-10 CVE-2026-68870 MEDIUM 5.3 Apache Airflow Microsoft Azure Provider — The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connec… 2026-08-10 CVE-2026-68871 MEDIUM 6.5 Apache Airflow Yandex Provider — The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Va… 2026-08-10 CVE-2026-68872 MEDIUM 6.5 Apache Airflow Amazon Provider — The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resol… 2026-08-10 CVE-2026-71558 CRITICAL 9.8 Apache Fory — Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ vers… 2026-08-07 CVE-2026-71559 HIGH 7.5 Apache Fory — Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to … 2026-08-07 CVE-2026-71560 CRITICAL 9.1 Apache Fory — Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versi… 2026-08-07 CVE-2026-32327 CRITICAL 9.1 Apache Portable Runtime Utility — A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer whi… 2026-08-06 CVE-2026-34191 CRITICAL 9.1 Apache Portable Runtime Utility — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache P… 2026-08-06 CVE-2026-34501 HIGH 7.5 Apache Portable Runtime Utility — Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects … 2026-08-06 CVE-2026-34502 HIGH 7.5 Apache Portable Runtime Utility — Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affec… 2026-08-06 CVE-2026-54225 HIGH 7.5 Apache Cxf — Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.… 2026-08-06 CVE-2026-57817 HIGH 8.1 Apache Cxf — The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when opera… 2026-08-06 CVE-2026-57818 HIGH 8.1 Apache Cxf — A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple t… 2026-08-06 CVE-2026-57819 HIGH 7.5 Apache Cxf — Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParamete… 2026-08-06 CVE-2026-61466 CRITICAL 9.1 Apache Cxf — In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `… 2026-08-06 CVE-2026-63687 CRITICAL 9.1 Apache Cxf — Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter… 2026-08-06 CVE-2026-64640 MEDIUM 5.3 Apache Polaris — Apache Polaris did not consistently validate storage locations supplied during table and view registration. A… 2026-08-06 CVE-2026-64958 HIGH 7.5 Apache Cxf — An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on … 2026-08-06 CVE-2026-65432 HIGH 7.5 Apache Cxf — Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external en… 2026-08-06 CVE-2026-65583 CRITICAL 9.1 Apache Cxf — Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required… 2026-08-06 CVE-2026-66909 CRITICAL 9.8 Apache Cxf — Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserializ… 2026-08-06 CVE-2026-68079 CRITICAL 9.8 Apache Cxf — In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited … 2026-08-06 CVE-2026-68481 HIGH 7.5 Apache Cxf — In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and Toke… 2026-08-06 CVE-2025-49506 HIGH 7.5 Apache Portable Runtime Utility — APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to h… 2026-08-06 CVE-2026-48834 HIGH 7.5 Apache Answer — Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache… 2026-08-05 CVE-2026-48911 HIGH 7.5 Apache Answer — Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answ… 2026-08-05 CVE-2026-48912 MEDIUM 6.5 Apache Answer — Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. … 2026-08-05 CVE-2026-50749 MEDIUM 6.5 Apache Answer — Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any … 2026-08-05 CVE-2026-60023 HIGH 7.5 Apache Answer — Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects… 2026-08-05 CVE-2026-60053 CRITICAL 9.1 Apache Answer — Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0… 2026-08-05 CVE-2026-61483 HIGH 7.5 Apache Lucy — ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apach… 2026-08-05 CVE-2026-61484 CRITICAL 9.8 Apache Lucy — ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue af… 2026-08-05 CVE-2026-61485 HIGH 7.5 Apache Lucy — ** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. Thi… 2026-08-05 CVE-2026-61486 CRITICAL 9.8 Apache Lucy — ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects … 2026-08-05 CVE-2026-66257 HIGH 7.5 Apache Qpid Proton J — A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leadi… 2026-08-05 CVE-2026-66273 HIGH 7.5 Apache Qpid Proton J — A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to… 2026-08-05 CVE-2026-66274 HIGH 7.5 Apache Qpid Proton J — A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to… 2026-08-05 CVE-2026-66275 MEDIUM 6.5 Apache Qpid Proton J — An authenticated attacker could exceed the session flow control incoming window potentially leading to denial … 2026-08-05 CVE-2026-66276 MEDIUM 6.5 Apache Qpid Proton J — An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usa… 2026-08-05 CVE-2026-66277 MEDIUM 6.5 Apache Qpid Proton J — It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authent… 2026-08-05 CVE-2026-67465 HIGH 7.5 Apache Qpid Proton Dotnet — A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leadi… 2026-08-05 CVE-2026-67551 HIGH 7.5 Apache Qpid Proton Dotnet — pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to p… 2026-08-05 CVE-2026-67552 HIGH 7.5 Apache Qpid Proton Dotnet — A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to… 2026-08-05 CVE-2026-67553 MEDIUM 6.5 Apache Qpid Proton Dotnet — An authenticated attacker could exceed the session flow control incoming window potentially leading to denial … 2026-08-05 CVE-2026-67554 MEDIUM 6.5 Apache Qpid Proton Dotnet — An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usa… 2026-08-05 CVE-2026-67555 MEDIUM 6.5 Apache Qpid Proton Dotnet — It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authent… 2026-08-05 CVE-2026-67588 HIGH 7.5 Apache Qpid Protonj2 — A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leadi… 2026-08-05 CVE-2026-67589 HIGH 7.5 Apache Qpid Protonj2 — A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to… 2026-08-05 CVE-2026-67590 HIGH 7.5 Apache Qpid Protonj2 — A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to… 2026-08-05 CVE-2026-67591 MEDIUM 6.5 Apache Qpid Protonj2 — An authenticated attacker could exceed the session flow control incoming window potentially leading to denial … 2026-08-05 CVE-2026-67592 HIGH 7.5 Apache Qpid Protonj2 — It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authent… 2026-08-05 CVE-2026-68060 HIGH 7.5 Apache Qpid Broker J — A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to… 2026-08-05 CVE-2026-68073 HIGH 7.5 Apache Qpid Broker J — A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to… 2026-08-05 CVE-2026-68074 HIGH 7.5 Apache Qpid Broker J — A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leadi… 2026-08-05 CVE-2026-68075 MEDIUM 6.5 Apache Qpid Broker J — An authenticated attacker could exceed the session flow control incoming window potentially leading to denial … 2026-08-05 CVE-2026-68077 MEDIUM 6.5 Apache Qpid Broker J — An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usa… 2026-08-05 CVE-2026-68078 MEDIUM 6.5 Apache Qpid Broker J — It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authent… 2026-08-05 CVE-2026-68080 MEDIUM 6.5 Apache Qpid Broker J — It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenti… 2026-08-05 CVE-2026-61372 HIGH 7.5 Apache Jena Fuseki — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fu… 2026-08-03 CVE-2026-62354 HIGH 7.7 Apache Nifi — Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows c… 2026-08-03 CVE-2026-68979 MEDIUM 5.9 Apache Nifi — Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce aut… 2026-08-03 CVE-2026-68980 LOW 2.3 Apache Nifi — Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Cont… 2026-08-03 CVE-2026-68981 HIGH 8.8 Apache Nifi — Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jerse… 2026-08-03 CVE-2026-44615 MEDIUM 6.5 Apache Zeppelin — Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated a… 2026-07-31 CVE-2026-62391 HIGH 8.1 Apache Kyuubi — The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuub… 2026-07-31 CVE-2026-64607 MEDIUM 5.3 Apache Httpcomponents Client — HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the con… 2026-07-31 CVE-2026-23981 MEDIUM 5.3 Apache Superset — An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissi… 2026-07-30 CVE-2026-23985 MEDIUM 5.3 Apache Superset — A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through … 2026-07-30 CVE-2026-28811 HIGH 7.5 Apache Jspwiki — Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgr… 2026-07-30 CVE-2026-28812 CRITICAL 9.8 Apache Jspwiki — UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to es… 2026-07-30 CVE-2026-28813 HIGH 8.8 Apache Jspwiki — Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are … 2026-07-30 CVE-2026-28814 HIGH 7.5 Apache Jspwiki — Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker t… 2026-07-30 CVE-2026-44613 MEDIUM 6.1 Apache Zeppelin — Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cro… 2026-07-30 CVE-2026-44616 MEDIUM 6.5 Apache Zeppelin — LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters wit… 2026-07-30 CVE-2026-44617 MEDIUM 6.5 Apache Zeppelin — LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping wh… 2026-07-30 CVE-2026-48910 MEDIUM 6.5 Apache Jspwiki — A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors … 2026-07-30 CVE-2026-52680 CRITICAL 9.8 Apache Kyuubi — Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a… 2026-07-30 CVE-2026-66755 MEDIUM 5.9 Apache Tika — Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1… 2026-07-30 CVE-2026-66756 MEDIUM 6.9 Apache Tika — Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.… 2026-07-30 CVE-2026-22068 MEDIUM 6.9 Apache Traffic Server — Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic … 2026-07-29 CVE-2026-23904 HIGH 7.3 Apache Kyuubi — Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destina… 2026-07-29 CVE-2026-24033 MEDIUM 6.9 Apache Traffic Server — Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traff… 2026-07-29 CVE-2026-33267 HIGH 7.7 Apache Traffic Server — Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: f… 2026-07-29 CVE-2026-33930 HIGH 8.2 Apache Traffic Server — Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redi… 2026-07-29 CVE-2026-41920 HIGH 7 Apache Traffic Server — Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: fro… 2026-07-29 CVE-2026-50622 HIGH 8.8 Apache Atlas — Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's ad… 2026-07-29 CVE-2026-57834 HIGH 7 Apache Traffic Server — Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache T… 2026-07-29 CVE-2026-58150 HIGH 7.8 Apache Traffic Server — Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggli… 2026-07-29 CVE-2026-58151 HIGH 8.7 Apache Traffic Server — Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-contr… 2026-07-29 CVE-2026-58152 MEDIUM 6.9 Apache Traffic Server — Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue a… 2026-07-29 CVE-2026-58153 MEDIUM 6.3 Apache Traffic Server — Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when co… 2026-07-29 CVE-2026-58154 CRITICAL 9.2 Apache Traffic Server — Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This … 2026-07-29 CVE-2026-58155 CRITICAL 9.2 Apache Traffic Server — Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and polic… 2026-07-29 CVE-2026-58156 MEDIUM 6.3 Apache Traffic Server — Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This … 2026-07-29 CVE-2026-58157 MEDIUM 6.9 Apache Traffic Server — Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connection… 2026-07-29 CVE-2026-58158 HIGH 8.2 Apache Traffic Server — Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack. This issue… 2026-07-29 CVE-2026-58159 HIGH 7 Apache Traffic Server — Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This is… 2026-07-29 CVE-2026-58160 MEDIUM 6.3 Apache Traffic Server — Apache Traffic Server reads out of bounds while parsing DNS answers. This issue affects Apache Traffic Server… 2026-07-29 CVE-2026-58161 CRITICAL 9.2 Apache Traffic Server — Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This … 2026-07-29 CVE-2026-58162 HIGH 8.4 Apache Traffic Server — The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. Th… 2026-07-29 CVE-2026-58163 HIGH 8.3 Apache Traffic Server — Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. Thi… 2026-07-29 CVE-2026-58164 HIGH 8.3 Apache Traffic Server — Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling.… 2026-07-29 CVE-2026-58175 HIGH 8.2 Apache Traffic Server — Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server… 2026-07-29 CVE-2026-58177 HIGH 8.3 Apache Traffic Server — The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors… 2026-07-29 CVE-2026-58178 HIGH 8.2 Apache Traffic Server — The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue… 2026-07-29 CVE-2026-58179 CRITICAL 9.2 Apache Traffic Server — The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This i… 2026-07-29 CVE-2026-58180 HIGH 8.2 Apache Traffic Server — The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affec… 2026-07-29 CVE-2026-58181 HIGH 8.2 Apache Traffic Server — The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. T… 2026-07-29 CVE-2026-58182 HIGH 8.2 Apache Traffic Server — The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. … 2026-07-29 CVE-2026-58183 HIGH 8.2 Apache Traffic Server — The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue aff… 2026-07-29 CVE-2026-58184 HIGH 8.3 Apache Traffic Server — The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR … 2026-07-29 CVE-2026-58185 HIGH 8.2 Apache Traffic Server — The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: fr… 2026-07-29 CVE-2026-58186 HIGH 8.2 Apache Traffic Server — The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses.… 2026-07-29 CVE-2026-58187 MEDIUM 6.3 Apache Traffic Server — The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling deni… 2026-07-29 CVE-2026-58188 HIGH 8.4 Apache Traffic Server — Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue aff… 2026-07-29 CVE-2026-58189 HIGH 8.2 Apache Traffic Server — Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplifi… 2026-07-29 CVE-2026-59243 CRITICAL 9.8 Apache Airflow Fab Provider — The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so … 2026-07-29 CVE-2026-65100 MEDIUM 6.3 Apache Traffic Server — Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded succes… 2026-07-29 CVE-2026-65324 HIGH 8.2 Apache Traffic Server — Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a sl… 2026-07-29 CVE-2026-65325 MEDIUM 6.3 Apache Traffic Server — Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate co… 2026-07-29 CVE-2026-59878 HIGH 7.5 Apache Activemq Amqp — Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remo… 2026-07-28 CVE-2026-61487 MEDIUM 6.5 Apache Activemq Broker — Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An aut… 2026-07-28 CVE-2026-66299 HIGH 7.5 Apache Tomcat — Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects… 2026-07-28 CVE-2026-66713 CRITICAL 9.8 Apache Axis2/Java — Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Fou… 2026-07-28 CVE-2026-41608 HIGH 7.5 Apache Thrift — Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python binding… 2026-07-27 CVE-2026-43871 HIGH 8.7 Apache Thrift — Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java… 2026-07-27 CVE-2026-45112 MEDIUM 6.9 Apache Thrift — Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue… 2026-07-27 CVE-2026-48144 CRITICAL 9.1 Apache Thrift — Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This is… 2026-07-27 CVE-2026-48145 HIGH 8.2 Apache Thrift — Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue… 2026-07-27 CVE-2026-48586 HIGH 8.7 Apache Thrift — Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Pyt… 2026-07-27 CVE-2026-49158 HIGH 7.5 Apache Thrift — Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings.… 2026-07-27 CVE-2026-55968 HIGH 8.7 Apache Thrift — Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apac… 2026-07-27 CVE-2026-55969 HIGH 8.7 Apache Thrift — Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe binding… 2026-07-27 CVE-2026-55970 MEDIUM 6.9 Apache Thrift — Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0… 2026-07-27 CVE-2026-55971 CRITICAL 9.3 Apache Thrift — Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: bef… 2026-07-27 CVE-2026-58023 MEDIUM 6.9 Apache Thrift — Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0… 2026-07-27 CVE-2026-58389 HIGH 8.7 Apache Thrift — Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue… 2026-07-27 CVE-2026-58662 HIGH 8.7 Apache Thrift — Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bind… 2026-07-27 CVE-2026-66053 MEDIUM 5.9 Apache Thrift — Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This is… 2026-07-27 CVE-2026-66390 MEDIUM 6.1 Apache Wicket — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache W… 2026-07-27 CVE-2026-66391 MEDIUM 6.5 Apache Wicket — Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue … 2026-07-27 CVE-2026-45811 HIGH 7.5 Apache Nimble — Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI… 2026-07-24 CVE-2026-45812 MEDIUM 6.5 Apache Nimble — Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report … 2026-07-24 CVE-2026-45813 HIGH 8.8 Apache Nimble — Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Impro… 2026-07-24 CVE-2026-45815 HIGH 7.5 Apache Nimble — Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (B… 2026-07-24 CVE-2026-45816 HIGH 7.5 Apache Nimble — NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disa… 2026-07-24 CVE-2026-46452 MEDIUM 5.3 Apache Nimble — Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing … 2026-07-24 CVE-2026-49326 MEDIUM 6.5 Apache Hbase — Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in t… 2026-07-24 CVE-2026-63317 MEDIUM 5.6 Apache Opennlp — Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions… 2026-07-24 CVE-2026-66142 HIGH 7.5 Apache Neethi — Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deepl… 2026-07-24 CVE-2026-66143 HIGH 7.5 Apache Neethi — It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Ne… 2026-07-24 CVE-2026-66144 HIGH 7.5 Apache Neethi — Although remote policy references are not retrieved during policy normalization, if they are manually retrieve… 2026-07-24 CVE-2026-60080 HIGH 7.3 Apache Fory — Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory … 2026-07-21 CVE-2026-64606 CRITICAL 9.8 Apache Fory — Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during… 2026-07-21 CVE-2026-64608 CRITICAL 9.8 Apache Fory — Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing dat… 2026-07-21 CVE-2026-64609 CRITICAL 9.1 Apache Fory — Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, rea… 2026-07-21 CVE-2026-53405 CRITICAL 9.8 Apache Syncope — Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate en… 2026-07-20 CVE-2026-53421 CRITICAL 9.8 Apache Syncope — Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate … 2026-07-20 CVE-2026-56452 HIGH 7.5 Apache Mina Sshd — Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-si… 2026-07-20 CVE-2026-56623 HIGH 7.1 Apache Mina Sshd — Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for clien… 2026-07-20 CVE-2026-56624 HIGH 7.3 Apache Mina Sshd — Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for clie… 2026-07-20 CVE-2026-57308 CRITICAL 9.8 Apache Syncope — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache S… 2026-07-20 CVE-2026-58624 MEDIUM 5.4 Apache Mina Sshd — Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side … 2026-07-20 CVE-2026-62183 CRITICAL 9.8 Apache Syncope — Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is… 2026-07-20 CVE-2026-62418 HIGH 8.1 Apache Syncope — Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connector… 2026-07-20 CVE-2026-63071 CRITICAL 9.8 Apache Syncope — Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate en… 2026-07-20 CVE-2026-59173 HIGH 7.5 Apache Traffic Server — Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic S… 2026-07-18 CVE-2026-62764 MEDIUM 5.7 Apache Accumulo — Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privi… 2026-07-17 CVE-2026-26032 MEDIUM 5.4 Apache Ivy — The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format de… 2026-07-15 CVE-2026-35152 HIGH 8.8 Apache Fineract — A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versio… 2026-07-15 CVE-2026-56287 HIGH 8.1 Apache Fineract — A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients… 2026-07-15 CVE-2026-57821 HIGH 8.1 Apache Fineract — A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions … 2026-07-15 CVE-2026-49488 MEDIUM 6.5 Apache Openmeetings — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMee… 2026-07-14 CVE-2026-58319 CRITICAL 9.1 Apache Doris — Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauth… 2026-07-14 CVE-2026-59083 CRITICAL 9.1 Apache Tomcat — Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed securi… 2026-07-14 CVE-2026-59084 CRITICAL 9.1 Apache Tomcat — Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configu… 2026-07-14 CVE-2026-62390 CRITICAL 9.8 Apache Kylin — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache K… 2026-07-14 CVE-2026-62392 HIGH 8.8 Apache Kylin — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Ap… 2026-07-14 CVE-2026-62393 MEDIUM 4.3 Apache Kylin — Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorizat… 2026-07-14 CVE-2026-41041 CRITICAL 9.1 Apache Gravitino — URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affe… 2026-07-13 CVE-2026-49876 MEDIUM 6.5 Apache Gravitino — Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud meta… 2026-07-13 CVE-2026-58065 HIGH 8.1 Apache Airflow Git Provider — The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, d… 2026-07-13 CVE-2026-59245 HIGH 8.1 Apache Airflow Fab Provider — In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permi… 2026-07-13 CVE-2026-28564 CRITICAL 9.8 Apache Iotdb — Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST B… 2026-07-10 CVE-2026-40005 CRITICAL 9.1 Apache Iotdb — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. … 2026-07-10 CVE-2026-40006 HIGH 7.5 Apache Iotdb — Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Aut… 2026-07-10 CVE-2026-40007 HIGH 7.5 Apache Iotdb — Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. When pipe_air_gap_rec… 2026-07-10 CVE-2026-40008 CRITICAL 9.8 Apache Iotdb — Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoT… 2026-07-10 CVE-2026-40009 MEDIUM 6.5 Apache Iotdb — Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can … 2026-07-10 CVE-2026-40452 HIGH 7.5 Apache Iotdb — Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/… 2026-07-10 CVE-2026-40454 HIGH 7.5 Apache Iotdb C++ Client — Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in… 2026-07-10 CVE-2026-49844 MEDIUM 6.3 Apache Log4j Api — Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API… 2026-07-10 CVE-2026-57111 HIGH 7.5 Apache Helix Rest — Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filt… 2026-07-09