Apache
219 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-73631
MEDIUM 4.3
Apache Struts — Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsi…
2026-08-15
CVE-2026-73632
MEDIUM 4.3
Apache Struts — Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response seri…
2026-08-15
CVE-2026-73634
HIGH 7.5
Apache Struts — Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint coll…
2026-08-15
CVE-2026-73635
HIGH 7.5
Apache Struts — Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is c…
2026-08-15
CVE-2026-73633
HIGH 7.5
Apache Struts — Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is co…
2026-08-14
CVE-2026-54183
MEDIUM 4.3
Apache Airflow — Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the U…
2026-08-12
CVE-2026-58076
HIGH 8.8
Apache Airflow — Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class nam…
2026-08-12
CVE-2026-59242
MEDIUM 5.4
Apache Airflow — Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal …
2026-08-12
CVE-2026-59244
MEDIUM 6.5
Apache Airflow — Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered …
2026-08-12
CVE-2026-65017
MEDIUM 6.5
Apache Airflow — Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments.…
2026-08-12
CVE-2026-67260
HIGH 7.3
Apache Airflow — Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swe…
2026-08-12
CVE-2026-67587
HIGH 8.8
Apache Airflow — Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, whic…
2026-08-12
CVE-2026-68076
MEDIUM 5.4
Apache Airflow — Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the w…
2026-08-12
CVE-2026-68868
MEDIUM 6.5
Apache Airflow Google Provider — The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team sco…
2026-08-12
CVE-2026-68968
HIGH 7.5
Apache Airflow — Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backf…
2026-08-12
CVE-2026-68969
MEDIUM 6.5
Apache Airflow — Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they w…
2026-08-12
CVE-2026-68970
MEDIUM 6.5
Apache Airflow — Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets store…
2026-08-12
CVE-2026-68971
MEDIUM 6.5
Apache Airflow — Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom re…
2026-08-12
CVE-2026-73237
MEDIUM 6.1
Apache Allura — XSS vulnerability in Markdown handling in Apache Allura.
This issue affects Apache Allura: from 1.10.0 before…
2026-08-12
CVE-2026-73238
MEDIUM 6.1
Apache Allura — XSS vulnerability in code display in Apache Allura.
This issue affects Apache Allura: before 1.19.1.
Users a…
2026-08-12
CVE-2026-73239
MEDIUM 6.5
Apache Allura — Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache…
2026-08-12
CVE-2026-73240
CRITICAL 9.8
Apache Allura — Specifically crafted inputs may lead to git argument injection in Apache Allura.
This issue affects Apache Al…
2026-08-12
CVE-2026-69223
CRITICAL 9.1
Apache Allura — Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).
This issue affects Apache Allu…
2026-08-11
CVE-2026-71290
CRITICAL 9.1
Apache Httpcomponents Client — Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerific…
2026-08-11
CVE-2026-28672
CRITICAL 9.8
Apache Ranger — Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ra…
2026-08-10
CVE-2026-32227
CRITICAL 9.8
Apache Ranger — SQL Injection vulnerability vulnerability in Apache Ranger.
This issue affects .
Users are recommended to up…
2026-08-10
CVE-2026-40920
CRITICAL 9.8
Apache Ranger — Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0.
Users are recommended …
2026-08-10
CVE-2026-42537
CRITICAL 9.8
Apache Ranger — Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0
Users are recommended to upgrade to ver…
2026-08-10
CVE-2026-44416
CRITICAL 9.8
Apache Ranger — Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <…
2026-08-10
CVE-2026-55799
CRITICAL 9.8
Apache Ranger — Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0
Users are recommende…
2026-08-10
CVE-2026-55814
HIGH 7.5
Apache Ranger — Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0.
Users are recommended to upgrade t…
2026-08-10
CVE-2026-61899
HIGH 7.5
Apache Tapestry — Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspat…
2026-08-10
CVE-2026-65942
HIGH 7.5
Apache Ranger — TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0.
Users are recommended to up…
2026-08-10
CVE-2026-65945
MEDIUM 6.5
Apache Ranger — Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0
Users are recommended to upgrade to vers…
2026-08-10
CVE-2026-65948
HIGH 7.3
Apache Ranger — UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.
Note: UnixAuth is NOT a recommende…
2026-08-10
CVE-2026-68871
MEDIUM 6.5
Apache Airflow Yandex Provider — The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Va…
2026-08-10
CVE-2026-68872
MEDIUM 6.5
Apache Airflow Amazon Provider — The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resol…
2026-08-10
CVE-2026-71558
CRITICAL 9.8
Apache Fory — Heap type confusion vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ vers…
2026-08-07
CVE-2026-71559
HIGH 7.5
Apache Fory — Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to …
2026-08-07
CVE-2026-71560
CRITICAL 9.1
Apache Fory — Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versi…
2026-08-07
CVE-2026-32327
CRITICAL 9.1
Apache Portable Runtime Utility — A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer whi…
2026-08-06
CVE-2026-34191
CRITICAL 9.1
Apache Portable Runtime Utility — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache P…
2026-08-06
CVE-2026-34501
HIGH 7.5
Apache Portable Runtime Utility — Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client.
This issue affects …
2026-08-06
CVE-2026-34502
HIGH 7.5
Apache Portable Runtime Utility — Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client
This issue affec…
2026-08-06
CVE-2026-54225
HIGH 7.5
Apache Cxf — Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.…
2026-08-06
CVE-2026-57817
HIGH 8.1
Apache Cxf — The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when opera…
2026-08-06
CVE-2026-57818
HIGH 8.1
Apache Cxf — A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple t…
2026-08-06
CVE-2026-57819
HIGH 7.5
Apache Cxf — Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParamete…
2026-08-06
CVE-2026-61466
CRITICAL 9.1
Apache Cxf — In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `…
2026-08-06
CVE-2026-63687
CRITICAL 9.1
Apache Cxf — Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter…
2026-08-06
CVE-2026-64640
MEDIUM 5.3
Apache Polaris — Apache Polaris did not consistently validate storage locations supplied during table and view registration.
A…
2026-08-06
CVE-2026-64958
HIGH 7.5
Apache Cxf — An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on …
2026-08-06
CVE-2026-65432
HIGH 7.5
Apache Cxf — Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external en…
2026-08-06
CVE-2026-65583
CRITICAL 9.1
Apache Cxf — Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required…
2026-08-06
CVE-2026-66909
CRITICAL 9.8
Apache Cxf — Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserializ…
2026-08-06
CVE-2026-68079
CRITICAL 9.8
Apache Cxf — In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited …
2026-08-06
CVE-2026-68481
HIGH 7.5
Apache Cxf — In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and Toke…
2026-08-06
CVE-2025-49506
HIGH 7.5
Apache Portable Runtime Utility — APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to h…
2026-08-06
CVE-2026-48834
HIGH 7.5
Apache Answer — Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer.
This issue affects Apache…
2026-08-05
CVE-2026-48911
HIGH 7.5
Apache Answer — Insufficient Verification of Data Authenticity vulnerability in Apache Answer.
This issue affects Apache Answ…
2026-08-05
CVE-2026-48912
MEDIUM 6.5
Apache Answer — Improper Input Validation vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
…
2026-08-05
CVE-2026-50749
MEDIUM 6.5
Apache Answer — Improper Authorization vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
Any …
2026-08-05
CVE-2026-60023
HIGH 7.5
Apache Answer — Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects…
2026-08-05
CVE-2026-60053
CRITICAL 9.1
Apache Answer — Insufficient Session Expiration vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0…
2026-08-05
CVE-2026-61483
HIGH 7.5
Apache Lucy — ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy.
This issue affects Apach…
2026-08-05
CVE-2026-61484
CRITICAL 9.8
Apache Lucy — ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy.
This issue af…
2026-08-05
CVE-2026-61485
HIGH 7.5
Apache Lucy — ** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy.
Thi…
2026-08-05
CVE-2026-61486
CRITICAL 9.8
Apache Lucy — ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy.
This issue affects …
2026-08-05
CVE-2026-66257
HIGH 7.5
Apache Qpid Proton J — A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leadi…
2026-08-05
CVE-2026-66273
HIGH 7.5
Apache Qpid Proton J — A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to…
2026-08-05
CVE-2026-66274
HIGH 7.5
Apache Qpid Proton J — A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to…
2026-08-05
CVE-2026-66275
MEDIUM 6.5
Apache Qpid Proton J — An authenticated attacker could exceed the session flow control incoming window potentially leading to denial …
2026-08-05
CVE-2026-66276
MEDIUM 6.5
Apache Qpid Proton J — An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usa…
2026-08-05
CVE-2026-66277
MEDIUM 6.5
Apache Qpid Proton J — It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authent…
2026-08-05
CVE-2026-67465
HIGH 7.5
Apache Qpid Proton Dotnet — A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leadi…
2026-08-05
CVE-2026-67551
HIGH 7.5
Apache Qpid Proton Dotnet — pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to p…
2026-08-05
CVE-2026-67552
HIGH 7.5
Apache Qpid Proton Dotnet — A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to…
2026-08-05
CVE-2026-67553
MEDIUM 6.5
Apache Qpid Proton Dotnet — An authenticated attacker could exceed the session flow control incoming window potentially leading to denial …
2026-08-05
CVE-2026-67554
MEDIUM 6.5
Apache Qpid Proton Dotnet — An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usa…
2026-08-05
CVE-2026-67555
MEDIUM 6.5
Apache Qpid Proton Dotnet — It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authent…
2026-08-05
CVE-2026-67588
HIGH 7.5
Apache Qpid Protonj2 — A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leadi…
2026-08-05
CVE-2026-67589
HIGH 7.5
Apache Qpid Protonj2 — A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to…
2026-08-05
CVE-2026-67590
HIGH 7.5
Apache Qpid Protonj2 — A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to…
2026-08-05
CVE-2026-67591
MEDIUM 6.5
Apache Qpid Protonj2 — An authenticated attacker could exceed the session flow control incoming window potentially leading to denial …
2026-08-05
CVE-2026-67592
HIGH 7.5
Apache Qpid Protonj2 — It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authent…
2026-08-05
CVE-2026-68060
HIGH 7.5
Apache Qpid Broker J — A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to…
2026-08-05
CVE-2026-68073
HIGH 7.5
Apache Qpid Broker J — A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to…
2026-08-05
CVE-2026-68074
HIGH 7.5
Apache Qpid Broker J — A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leadi…
2026-08-05
CVE-2026-68075
MEDIUM 6.5
Apache Qpid Broker J — An authenticated attacker could exceed the session flow control incoming window potentially leading to denial …
2026-08-05
CVE-2026-68077
MEDIUM 6.5
Apache Qpid Broker J — An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usa…
2026-08-05
CVE-2026-68078
MEDIUM 6.5
Apache Qpid Broker J — It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authent…
2026-08-05
CVE-2026-68080
MEDIUM 6.5
Apache Qpid Broker J — It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenti…
2026-08-05
CVE-2026-61372
HIGH 7.5
Apache Jena Fuseki — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fu…
2026-08-03
CVE-2026-62354
HIGH 7.7
Apache Nifi — Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows c…
2026-08-03
CVE-2026-68979
MEDIUM 5.9
Apache Nifi — Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce aut…
2026-08-03
CVE-2026-68980
LOW 2.3
Apache Nifi — Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Cont…
2026-08-03
CVE-2026-68981
HIGH 8.8
Apache Nifi — Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jerse…
2026-08-03
CVE-2026-44615
MEDIUM 6.5
Apache Zeppelin — Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated a…
2026-07-31
CVE-2026-62391
HIGH 8.1
Apache Kyuubi — The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuub…
2026-07-31
CVE-2026-64607
MEDIUM 5.3
Apache Httpcomponents Client — HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the con…
2026-07-31
CVE-2026-23981
MEDIUM 5.3
Apache Superset — An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissi…
2026-07-30
CVE-2026-23985
MEDIUM 5.3
Apache Superset — A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through …
2026-07-30
CVE-2026-28811
HIGH 7.5
Apache Jspwiki — Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3.
Users are recommended to upgr…
2026-07-30
CVE-2026-28812
CRITICAL 9.8
Apache Jspwiki — UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to es…
2026-07-30
CVE-2026-28813
HIGH 8.8
Apache Jspwiki — Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities.
Users are …
2026-07-30
CVE-2026-28814
HIGH 7.5
Apache Jspwiki — Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker t…
2026-07-30
CVE-2026-44613
MEDIUM 6.1
Apache Zeppelin — Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cro…
2026-07-30
CVE-2026-44616
MEDIUM 6.5
Apache Zeppelin — LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters wit…
2026-07-30
CVE-2026-44617
MEDIUM 6.5
Apache Zeppelin — LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping wh…
2026-07-30
CVE-2026-48910
MEDIUM 6.5
Apache Jspwiki — A carefully crafted editing request could trigger an XSS vulnerability
on Apache JSPWiki when parsing errors …
2026-07-30
CVE-2026-52680
CRITICAL 9.8
Apache Kyuubi — Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a…
2026-07-30
CVE-2026-66755
MEDIUM 5.9
Apache Tika — Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1…
2026-07-30
CVE-2026-66756
MEDIUM 6.9
Apache Tika — Improper Protection of Alternate Path vulnerability in Apache Tika.
This issue affects Apache Tika: from 4.0.…
2026-07-30
CVE-2026-22068
MEDIUM 6.9
Apache Traffic Server — Regular Expression without Anchors vulnerability in Apache Traffic Server.
This issue affects Apache Traffic …
2026-07-29
CVE-2026-23904
HIGH 7.3
Apache Kyuubi — Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destina…
2026-07-29
CVE-2026-24033
MEDIUM 6.9
Apache Traffic Server — Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traff…
2026-07-29
CVE-2026-33267
HIGH 7.7
Apache Traffic Server — Improper Input Validation vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: f…
2026-07-29
CVE-2026-33930
HIGH 8.2
Apache Traffic Server — Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redi…
2026-07-29
CVE-2026-41920
HIGH 7
Apache Traffic Server — Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: fro…
2026-07-29
CVE-2026-50622
HIGH 8.8
Apache Atlas — Description:
Missing Authorization in Apache Atlas.
A missing authorization vulnerability in Apache Atlas's ad…
2026-07-29
CVE-2026-57834
HIGH 7
Apache Traffic Server — Apache Traffic Server allows request smuggling if chunked messages are malformed.
This issue affects Apache T…
2026-07-29
CVE-2026-58150
HIGH 7.8
Apache Traffic Server — Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggli…
2026-07-29
CVE-2026-58151
HIGH 8.7
Apache Traffic Server — Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-contr…
2026-07-29
CVE-2026-58152
MEDIUM 6.9
Apache Traffic Server — Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory.
This issue a…
2026-07-29
CVE-2026-58153
MEDIUM 6.3
Apache Traffic Server — Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when co…
2026-07-29
CVE-2026-58154
CRITICAL 9.2
Apache Traffic Server — Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers.
This …
2026-07-29
CVE-2026-58155
CRITICAL 9.2
Apache Traffic Server — Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and polic…
2026-07-29
CVE-2026-58156
MEDIUM 6.3
Apache Traffic Server — Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass.
This …
2026-07-29
CVE-2026-58157
MEDIUM 6.9
Apache Traffic Server — Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connection…
2026-07-29
CVE-2026-58158
HIGH 8.2
Apache Traffic Server — Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack.
This issue…
2026-07-29
CVE-2026-58159
HIGH 7
Apache Traffic Server — Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors.
This is…
2026-07-29
CVE-2026-58160
MEDIUM 6.3
Apache Traffic Server — Apache Traffic Server reads out of bounds while parsing DNS answers.
This issue affects Apache Traffic Server…
2026-07-29
CVE-2026-58161
CRITICAL 9.2
Apache Traffic Server — Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling.
This …
2026-07-29
CVE-2026-58162
HIGH 8.4
Apache Traffic Server — The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI.
Th…
2026-07-29
CVE-2026-58163
HIGH 8.3
Apache Traffic Server — Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing.
Thi…
2026-07-29
CVE-2026-58164
HIGH 8.3
Apache Traffic Server — Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling.…
2026-07-29
CVE-2026-58175
HIGH 8.2
Apache Traffic Server — Apache Traffic Server leaks memory when handling HostDB SRV records.
This issue affects Apache Traffic Server…
2026-07-29
CVE-2026-58177
HIGH 8.3
Apache Traffic Server — The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors…
2026-07-29
CVE-2026-58178
HIGH 8.2
Apache Traffic Server — The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs.
This issue…
2026-07-29
CVE-2026-58179
CRITICAL 9.2
Apache Traffic Server — The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input.
This i…
2026-07-29
CVE-2026-58180
HIGH 8.2
Apache Traffic Server — The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input.
This issue affec…
2026-07-29
CVE-2026-58181
HIGH 8.2
Apache Traffic Server — The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input.
T…
2026-07-29
CVE-2026-58182
HIGH 8.2
Apache Traffic Server — The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state.
…
2026-07-29
CVE-2026-58183
HIGH 8.2
Apache Traffic Server — The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input.
This issue aff…
2026-07-29
CVE-2026-58184
HIGH 8.3
Apache Traffic Server — The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR …
2026-07-29
CVE-2026-58185
HIGH 8.2
Apache Traffic Server — The Apache Traffic Server intercept plugin has a use-after-free.
This issue affects Apache Traffic Server: fr…
2026-07-29
CVE-2026-58186
HIGH 8.2
Apache Traffic Server — The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses.…
2026-07-29
CVE-2026-58187
MEDIUM 6.3
Apache Traffic Server — The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling deni…
2026-07-29
CVE-2026-58188
HIGH 8.4
Apache Traffic Server — Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors.
This issue aff…
2026-07-29
CVE-2026-58189
HIGH 8.2
Apache Traffic Server — Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplifi…
2026-07-29
CVE-2026-59243
CRITICAL 9.8
Apache Airflow Fab Provider — The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so …
2026-07-29
CVE-2026-65100
MEDIUM 6.3
Apache Traffic Server — Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded succes…
2026-07-29
CVE-2026-65324
HIGH 8.2
Apache Traffic Server — Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a sl…
2026-07-29
CVE-2026-65325
MEDIUM 6.3
Apache Traffic Server — Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate co…
2026-07-29
CVE-2026-59878
HIGH 7.5
Apache Activemq Amqp — Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All.
A remo…
2026-07-28
CVE-2026-61487
MEDIUM 6.5
Apache Activemq Broker — Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.
An aut…
2026-07-28
CVE-2026-66299
HIGH 7.5
Apache Tomcat — Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.
This issue affects…
2026-07-28
CVE-2026-66713
CRITICAL 9.8
Apache Axis2/Java — Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component
in Apache Software Fou…
2026-07-28
CVE-2026-41608
HIGH 7.5
Apache Thrift — Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python binding…
2026-07-27
CVE-2026-43871
HIGH 8.7
Apache Thrift — Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java…
2026-07-27
CVE-2026-45112
MEDIUM 6.9
Apache Thrift — Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.
This issue…
2026-07-27
CVE-2026-48144
CRITICAL 9.1
Apache Thrift — Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings.
This is…
2026-07-27
CVE-2026-48145
HIGH 8.2
Apache Thrift — Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings.
This issue…
2026-07-27
CVE-2026-48586
HIGH 8.7
Apache Thrift — Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Pyt…
2026-07-27
CVE-2026-49158
HIGH 7.5
Apache Thrift — Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings.…
2026-07-27
CVE-2026-55968
HIGH 8.7
Apache Thrift — Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apac…
2026-07-27
CVE-2026-55969
HIGH 8.7
Apache Thrift — Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe binding…
2026-07-27
CVE-2026-55970
MEDIUM 6.9
Apache Thrift — Buffer Over-read vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0…
2026-07-27
CVE-2026-55971
CRITICAL 9.3
Apache Thrift — Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: bef…
2026-07-27
CVE-2026-58023
MEDIUM 6.9
Apache Thrift — Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0…
2026-07-27
CVE-2026-58389
HIGH 8.7
Apache Thrift — Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings.
This issue…
2026-07-27
CVE-2026-58662
HIGH 8.7
Apache Thrift — Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bind…
2026-07-27
CVE-2026-66053
MEDIUM 5.9
Apache Thrift — Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.
This is…
2026-07-27
CVE-2026-66390
MEDIUM 6.1
Apache Wicket — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache W…
2026-07-27
CVE-2026-66391
MEDIUM 6.5
Apache Wicket — Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket.
This issue …
2026-07-27
CVE-2026-45811
HIGH 7.5
Apache Nimble — Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE.
The HCI…
2026-07-24
CVE-2026-45812
MEDIUM 6.5
Apache Nimble — Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report …
2026-07-24
CVE-2026-45813
HIGH 8.8
Apache Nimble — Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service.
Impro…
2026-07-24
CVE-2026-45815
HIGH 7.5
Apache Nimble — Reachable Assertion vulnerability in Apache NimBLE.
A specially crafted ATT Read Multiple Variable Response (B…
2026-07-24
CVE-2026-45816
HIGH 7.5
Apache Nimble — NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.
This requires disa…
2026-07-24
CVE-2026-46452
MEDIUM 5.3
Apache Nimble — Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing …
2026-07-24
CVE-2026-49326
MEDIUM 6.5
Apache Hbase — Missing Authorization vulnerability in Apache HBase thrift and rest delegation service.
A scan operation in t…
2026-07-24
CVE-2026-63317
MEDIUM 5.6
Apache Opennlp — Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP
Versions…
2026-07-24
CVE-2026-66142
HIGH 7.5
Apache Neethi — Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deepl…
2026-07-24
CVE-2026-66143
HIGH 7.5
Apache Neethi — It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Ne…
2026-07-24
CVE-2026-66144
HIGH 7.5
Apache Neethi — Although remote policy references are not retrieved during policy normalization, if they are manually retrieve…
2026-07-24
CVE-2026-60080
HIGH 7.3
Apache Fory — Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory …
2026-07-21
CVE-2026-64606
CRITICAL 9.8
Apache Fory — Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during…
2026-07-21
CVE-2026-64608
CRITICAL 9.8
Apache Fory — Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing dat…
2026-07-21
CVE-2026-64609
CRITICAL 9.1
Apache Fory — Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, rea…
2026-07-21
CVE-2026-53405
CRITICAL 9.8
Apache Syncope — Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate en…
2026-07-20
CVE-2026-53421
CRITICAL 9.8
Apache Syncope — Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate …
2026-07-20
CVE-2026-56452
HIGH 7.5
Apache Mina Sshd — Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-si…
2026-07-20
CVE-2026-56623
HIGH 7.1
Apache Mina Sshd — Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for clien…
2026-07-20
CVE-2026-56624
HIGH 7.3
Apache Mina Sshd — Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for clie…
2026-07-20
CVE-2026-57308
CRITICAL 9.8
Apache Syncope — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache S…
2026-07-20
CVE-2026-58624
MEDIUM 5.4
Apache Mina Sshd — Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side …
2026-07-20
CVE-2026-62183
CRITICAL 9.8
Apache Syncope — Improper Privilege Management vulnerability in Apache Syncope.
When:
* the all-Java user workflow adapter is…
2026-07-20
CVE-2026-62418
HIGH 8.1
Apache Syncope — Low-privileged authenticated Server-Side Request Forgery (SSRF)
vulnerability in Apache Syncope via Connector…
2026-07-20
CVE-2026-63071
CRITICAL 9.8
Apache Syncope — Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate en…
2026-07-20
CVE-2026-59173
HIGH 7.5
Apache Traffic Server — Uncontrolled Resource Consumption vulnerability in Apache Traffic Server.
This issue affects Apache Traffic S…
2026-07-18
CVE-2026-62764
MEDIUM 5.7
Apache Accumulo — Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo.
An authenticated, but low-privi…
2026-07-17
CVE-2026-26032
MEDIUM 5.4
Apache Ivy — The PackagerResolver of Apache Ivy is able to download online
artifacts and to (re)package them in a format de…
2026-07-15
CVE-2026-35152
HIGH 8.8
Apache Fineract — A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versio…
2026-07-15
CVE-2026-56287
HIGH 8.1
Apache Fineract — A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients…
2026-07-15
CVE-2026-57821
HIGH 8.1
Apache Fineract — A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions …
2026-07-15
CVE-2026-49488
MEDIUM 6.5
Apache Openmeetings — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMee…
2026-07-14
CVE-2026-58319
CRITICAL 9.1
Apache Doris — Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauth…
2026-07-14
CVE-2026-59083
CRITICAL 9.1
Apache Tomcat — Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed securi…
2026-07-14
CVE-2026-59084
CRITICAL 9.1
Apache Tomcat — Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configu…
2026-07-14
CVE-2026-62390
CRITICAL 9.8
Apache Kylin — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache K…
2026-07-14
CVE-2026-62392
HIGH 8.8
Apache Kylin — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Ap…
2026-07-14
CVE-2026-62393
MEDIUM 4.3
Apache Kylin — Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorizat…
2026-07-14
CVE-2026-41041
CRITICAL 9.1
Apache Gravitino — URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino.
This issue affe…
2026-07-13
CVE-2026-49876
MEDIUM 6.5
Apache Gravitino — Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud meta…
2026-07-13
CVE-2026-58065
HIGH 8.1
Apache Airflow Git Provider — The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, d…
2026-07-13
CVE-2026-59245
HIGH 8.1
Apache Airflow Fab Provider — In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permi…
2026-07-13
CVE-2026-49844
MEDIUM 6.3
Apache Log4j Api — Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API…
2026-07-10
CVE-2026-57111
HIGH 7.5
Apache Helix Rest — Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filt…
2026-07-09