Vulnerabilities in Apache Software Foundation

2,436 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-102497HIGHApache XMLSchema: Denial of service through cyclic schema definitions in the schema walkerEPSS —CVE-2026-88920—Apache WSS4J: SAML Sender-Vouches Authentication BypassEPSS —CVE-2026-93995MEDIUMApache MINA SSHD: Remote execution of JGit "archive -o=file.zip" can write file on the serverEPSS —CVE-2026-87830—Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protection checks.EPSS —CVE-2026-95616HIGHApache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.509 certificate extensionsEPSS —CVE-2026-94053CRITICALApache MINA SSHD: LDAP injection in sshd-ldapEPSS —CVE-2026-89238—Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selectionEPSS —CVE-2026-93994HIGHApache MINA SSHD: Repeated-publickey policy bypass on serverEPSS —CVE-2026-102510HIGHApache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled lengthsEPSS —CVE-2026-92899MEDIUMApache WSS4J: UsernameToken replay protection bypassed by re-encoding the NonceEPSS —CVE-2026-77185CRITICALApache MINA SSHD: Asynchronous authentication can bypass signature verificationEPSS —CVE-2026-78214MEDIUMApache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded PathsEPSS —CVE-2026-94052CRITICALApache MINA SSHD: LDAP password authentication ineffectiveEPSS —CVE-2026-93996MEDIUMApache MINA SSHD: Memory exhaustion DoS via unbounded SCP command line readEPSS —CVE-2026-71897MEDIUMApache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and batch-move endpointsEPSS —CVE-2026-71898MEDIUMApache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute Workflows and Tamper with Workflow DefinitionsEPSS —