Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-24033MEDIUMApache Traffic Server: Request smuggling via chunked extension quoted-string parsingEPSS 0.6%CVE-2022-43719HIGHApache Superset: Cross Site Request Forgery (CSRF) on accept, request access APIEPSS 0.6%CVE-2026-46764MEDIUMApache Airflow: Event Log detail endpoint bypasses DAG-scoped event log permission filterEPSS 0.6%CVE-2026-38743MEDIUMApache Airflow: Dags endpoint might provide access to otherwise inaccessible entitiesEPSS 0.6%CVE-2026-41014MEDIUMApache Airflow: per-DAG RBAC bypass on /ui/partitioned_dag_runs endpointsEPSS 0.6%CVE-2026-40690MEDIUMApache Airflow: Assets graph view bypasses DAG level access control displaying unrelated topologies and all DAGs names to unauthorized usersEPSS 0.6%CVE-2024-46910HIGHApache Atlas: An authenticated user can perform XSS and potentially impersonate another userEPSS 0.6%CVE-2026-58150HIGHApache Traffic Server: HTTP/2 requests with Transfer-Encoding are not rejected, allowing request smugglingEPSS 0.6%CVE-2026-61398CRITICALApache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Instance Reset Password Function in UIEPSS 0.6%CVE-2026-31906MEDIUMApache OFBiz: Reflected XSS via Improper HTML Attribute Escaping in Layered-Modal Dialog ParametersEPSS 0.6%CVE-2026-60053CRITICALApache Answer: Residual Administrative API Key Access After Role or Account RevocationEPSS 0.6%CVE-2026-49364CRITICALApache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-Authentication Cluster Credential Exposure to Discovered PeersEPSS 0.6%CVE-2026-22022HIGHApache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPluginEPSS 0.6%CVE-2026-81866LOWApache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector ConfigurationEPSS 0.6%CVE-2026-42797MEDIUMApache Syncope: JexlContextBuilder Information DisclosureEPSS 0.6%CVE-2026-54475HIGHApache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary destination ownership takeoverEPSS 0.6%CVE-2026-58159HIGHApache Traffic Server: Listener and ACL handling allow access-control bypassEPSS 0.6%CVE-2026-46584LOWApache Camel Mail: The mail producer applied attacker-supplied message headers as JavaMail session properties, allowing an attacker to influence SMTP parametersEPSS 0.6%CVE-2025-53648MEDIUMApache Gravitino: SQL misconfiguration can access or truncate filesEPSS 0.6%CVE-2025-66336HIGHApache Doris MCP Server: SQL injection leading the authentication bypassEPSS 0.6%