Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-63044MEDIUMApache InLong: Authenticated SSRF via POST /api/node/testConnectionEPSS 0.5%CVE-2026-43513HIGHApache Tomcat: LockOutRealm treats user names as case-sensitiveEPSS 0.5%CVE-2026-34477MEDIUMApache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypassEPSS 0.5%CVE-2026-46605MEDIUMApache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incomplete authorization during destination removalEPSS 0.5%CVE-2026-61399MEDIUMApache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Lock User Function in UIEPSS 0.5%CVE-2026-82434CRITICALApache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to LogsEPSS 0.5%CVE-2026-25199CRITICALApache CloudStack: Proxmox Extension Allows Unauthorized Cross-Tenant Instance AccessEPSS 0.5%CVE-2026-80354HIGHApache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespaceEPSS 0.5%CVE-2026-91867MEDIUMApache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitelyEPSS 0.5%CVE-2025-48459MEDIUMApache IoTDB: Deserialization of untrusted DataEPSS 0.5%CVE-2026-44598MEDIUMApache Shiro Jakarta EE module: Open redirect and SSRF (requires valid credentials)EPSS 0.5%CVE-2026-49876MEDIUMApache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIsEPSS 0.5%CVE-2026-40564MEDIUMApache Flink Kubernetes Operator: Server-Side Request Forgery and local file access in Kubernetes OperatorEPSS 0.5%CVE-2026-42357MEDIUMApache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.EPSS 0.5%CVE-2026-49326MEDIUMApache HBase: Missing scanner instance owner check in thrift delegation serviceEPSS 0.5%CVE-2025-53689HIGHApache Jackrabbit: XXE vulnerability in jackrabbit-spi-commonsEPSS 0.5%CVE-2025-60012MEDIUMApache Livy: Restrict file accessEPSS 0.5%CVE-2026-92230HIGHApache Karaf: Improper release of ClassLoader references via static ThreadLocal cachingEPSS 0.5%CVE-2026-40007HIGHApache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowErrorEPSS 0.5%CVE-2026-40454HIGHApache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server dataEPSS 0.5%