Vulnerabilities in Apache Software Foundation

1,899 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-34033MEDIUMApache Answer: HTML Content Injection in EmailEPSS 0.4%CVE-2026-54226MEDIUMApache Kvrocks: RESTORE IntSet Integer Overflow Leads to Remote DoSEPSS 0.3%CVE-2025-53648MEDIUMApache Gravitino: SQL misconfiguration can access or truncate filesEPSS 0.3%CVE-2026-23984HIGHApache Superset: SQLLab Read-Only Bypass on PostgreSQLEPSS 0.3%CVE-2025-49124HIGHApache Tomcat: exe side-loading via icalcs.exe in Tomcat installer for WindowsEPSS 0.3%CVE-2017-3166In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that makEPSS 0.3%CVE-2026-34476HIGHApache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP ServerEPSS 0.3%CVE-2023-43123Apache Storm: Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary filesEPSS 0.3%CVE-2026-45426LOWApache Airflow: Log server JWT authorization bypass via Python lstrip() character stripping allows cross-Dag log accessEPSS 0.3%CVE-2024-27906MEDIUMApache Airflow: Dag Code and Import Error Permissions IgnoredEPSS 0.3%CVE-2025-62728MEDIUMApache Hive: SQL injection vulnerability when processing delete column statistics requests via the HMS Thrift APIsEPSS 0.3%CVE-2026-40048HIGHApache Camel PQC: Unsafe Deserialization from FileBasedKeyLifecycleManagerEPSS 0.3%CVE-2026-44618MEDIUMApache CXF: XXE vulnerability in WS-Transfer functionalityEPSS 0.3%CVE-2026-32967MEDIUMApache DolphinScheduler: The `/v2` experimental interface lacks permission checksEPSS 0.3%CVE-2026-42360MEDIUMApache Airflow: Rendered template truncation bypasses nested sensitive-key maskingEPSS 0.3%CVE-2026-46605MEDIUMApache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incomplete authorization during destination removalEPSS 0.3%CVE-2026-42358MEDIUMApache Airflow: Variable masker depth-limit bypass returns cleartext nested secretsEPSS 0.3%CVE-2025-58137HIGHApache Fineract: IDOR via self-service APIEPSS 0.3%CVE-2023-49582MEDIUMApache Portable Runtime (APR): Unexpected lax shared memory permissionsEPSS 0.3%CVE-2025-53470LOWApache Mynewt NimBLE: Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driverEPSS 0.3%