Vulnerabilities in Apache Software Foundation

2,436 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-94243HIGHApache Sling Security Bundle: RefererFilter accepts weaker-than-origin evidenceEPSS 0.1%CVE-2026-82429HIGHApache Storm Worker Launcher: Local Privilege Escalation to Root via a Time-of-Check Race in the Worker LauncherEPSS 0.1%CVE-2026-73581MEDIUMApache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystoreEPSS 0.1%CVE-2026-102511HIGHApache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed responses and derives the connection target from themEPSS —CVE-2026-94029MEDIUMApache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-handle extensionEPSS —CVE-2026-102495HIGHApache XMLSchema: Denial of service through unbounded recursion when resolving schema imports and includesEPSS —CVE-2026-71899—Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to Information DisclosureEPSS —CVE-2026-102509HIGHApache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parserEPSS —CVE-2026-102508CRITICALApache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgradeEPSS —CVE-2026-85532—Apache WSS4J: Insufficient Validation of Derived-Key ParametersEPSS —CVE-2026-81569MEDIUMApache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized Workflow ExecutionEPSS —CVE-2026-82804HIGHApache DolphinScheduler: Command Injection in the Alert Script PluginEPSS —CVE-2026-66083MEDIUMApache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasources/unauth-datasourceEPSS —CVE-2026-94002HIGHApache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP repliesEPSS —CVE-2026-81930MEDIUMApache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer token off-domainEPSS —CVE-2026-102496HIGHApache XMLSchema: Denial of service through deeply nested schema structuresEPSS —CVE-2026-92121—Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an STR-Transform referenceEPSS —CVE-2026-86843MEDIUMApache Airflow Teradata provider: SQL injection via unvalidated Dag Params in the compute-cluster example DagEPSS —CVE-2026-97395—Apache Polaris: Allows authorized table writers to redirect server-side Iceberg FileIO requests to attacker-controlled endpoints using operation-scoped storage credentialsEPSS —CVE-2026-81862MEDIUMApache Airflow Teradata provider: Teradata transfer operators embed cloud storage credentials in SQL text, task logs and Teradata query logsEPSS —