Vulnerabilities in Apache Software Foundation

1,894 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2025-59789HIGHApache bRPC: Stack Exhaustion via Unbounded Recursion in JSON ParserEPSS 1.5%CVE-2009-4267The console in Apache jUDDI 3.0.0 does not properly escape line feeds, which allows remote authenticated users to spoof log entries via the EPSS 1.5%CVE-2021-41972Credentials leakEPSS 1.4%CVE-2022-42252HIGHApache Tomcat request smuggling via malformed content-lengthEPSS 1.4%CVE-2023-30771CRITICALApache IoTDB Workbench: apache/iotdb-web-workbench: forge the JWTToken to access workbenchEPSS 1.4%CVE-2025-46762HIGHApache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadataEPSS 1.4%CVE-2023-22849MEDIUMApache Sling App CMS: XSS in CMS Reference / UI ComponentsEPSS 1.4%CVE-2024-31866CRITICALApache Zeppelin: Interpreter download command does not escape malicious code injectionEPSS 1.4%CVE-2022-43982MEDIUMApache Airflow prior to 2.4.2 allows reflected XSS via Origin Query Argument in URLEPSS 1.4%CVE-2022-26850Insufficiently protected credentialsEPSS 1.4%CVE-2023-42792Apache Airflow: Improper access control to DAG resourcesEPSS 1.4%CVE-2023-34340CRITICALApache Accumulo: Accumulo 2.1.0 may incorrectly validate cached credentialsEPSS 1.4%CVE-2017-12625Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking policies can be definedEPSS 1.4%CVE-2025-64775HIGHApache Struts: File leak in multipart request processing causes disk exhaustion (DoS)EPSS 1.4%CVE-2017-7667Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same oriEPSS 1.4%CVE-2023-26268MEDIUMApache CouchDB, IBM Cloudant: Information sharing via couchjs processesEPSS 1.4%CVE-2026-47323CRITICALApache Camel: Camel-CXF Message Header Injection via Missing Inbound FilteringEPSS 1.4%CVE-2024-51941HIGHApache Ambari: Remote Code Injection in Ambari Metrics and AMS AlertsEPSS 1.4%CVE-2022-37401Apache OpenOffice Weak Master KeysEPSS 1.4%CVE-2024-50386HIGHApache CloudStack: Directly downloaded templates can be used to abuse KVM-based infrastructureEPSS 1.4%