Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2025-64152CRITICALApache IoTDB: Path Traversal VulnerabilityEPSS 0.5%CVE-2026-58155CRITICALApache Traffic Server: Header-name length truncation enables header aliasing and request smugglingEPSS 0.5%CVE-2026-58154CRITICALApache Traffic Server: Memory-safety errors in MIME and header parsingEPSS 0.5%CVE-2025-61735HIGHApache Kylin: Server-Side Request ForgeryEPSS 0.5%CVE-2021-28129—DEB packaging for Apache OpenOffice 4.1.8 installed with a non-root userid and groupidEPSS 0.5%CVE-2026-41920HIGHApache Traffic Server: SNI to Host header matching policy is not properly enforcedEPSS 0.5%CVE-2026-43514LOWApache Tomcat: AJP secret compared in non-constant timeEPSS 0.5%CVE-2026-77791HIGHApache Tomcat: DoS via busy wait during WebSocket closeEPSS 0.5%CVE-2026-43827MEDIUMApache Shiro: Session fixation: new session is not created after login by defaultEPSS 0.5%CVE-2025-66171MEDIUMApache CloudStack: Any user can create a new VM from backups they should not have access toEPSS 0.5%CVE-2025-55675MEDIUMApache Superset: Incorrect datasource authorization on REST APIEPSS 0.5%CVE-2026-45813HIGHApache NimBLE: Incorrect data validation in BASS add/modify source operationEPSS 0.5%CVE-2025-48977HIGHApache Ignite: REST HTTP arbitrary file read vulnerabilityEPSS 0.5%CVE-2026-57915HIGHApache Kerby: Kerberos Pre-Authentication BypassEPSS 0.5%CVE-2025-47436MEDIUMApache ORC: Potential Heap Buffer Overflow during C++ LZO DecompressionEPSS 0.5%CVE-2024-53679HIGHApache VCL: XSS vulnerability in User Lookup impacting user privilegesEPSS 0.5%CVE-2026-49872MEDIUMApache APISIX: Improper authentication in cas-auth pluginEPSS 0.5%CVE-2025-24853HIGHApache JSPWiki: Cross-Site Scripting (XSS) in JSPWiki Header Link processingEPSS 0.5%CVE-2026-42360MEDIUMApache Airflow: Rendered template truncation bypasses nested sensitive-key maskingEPSS 0.5%CVE-2026-42358MEDIUMApache Airflow: Variable masker depth-limit bypass returns cleartext nested secretsEPSS 0.5%