Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-62354HIGHApache NiFi: Incorrect Authorization for Parameter Context Validation RequestsEPSS 0.5%CVE-2026-62393MEDIUMApache Kylin: Improper authorization in job information retrievalEPSS 0.5%CVE-2026-41115MEDIUMApache Kafka: Improper Authorization in CONSUMER_GROUP_DESCRIBE APIEPSS 0.5%CVE-2026-48589NONEApache Shiro: Jakarta EE open redirect via untrusted Referer in post-login redirect flowEPSS 0.5%CVE-2026-23982HIGHApache Superset: Improper Authorization in Dataset Creation Allows Access Control BypassEPSS 0.5%CVE-2026-65613MEDIUMApache CloudStack: Webhook Deliveries Incorrect AccessEPSS 0.5%CVE-2026-77147MEDIUMApache Syncope: Groovy Sandbox escape for empty CommandArgsEPSS 0.4%CVE-2025-55753HIGHApache HTTP Server: mod_md (ACME), unintended retry intervalsEPSS 0.4%CVE-2024-46911MEDIUMApache Roller: Weakness in CSRF protection allows privilege escalationEPSS 0.4%CVE-2025-24854MEDIUMApache JSPWiki: Cross-Site Scripting (XSS) in JSPWiki Image pluginEPSS 0.4%CVE-2026-41081MEDIUMApache Storm Client: Anonymous principal assigned on TLS client certificate verification failureEPSS 0.4%CVE-2026-23902HIGHApache DolphinScheduler: Users are able to use tenants that are not defined on the platform during workflow execution.EPSS 0.4%CVE-2025-62232HIGHApache APISIX: basic-auth logs plaintext credentials at info levelEPSS 0.4%CVE-2026-49486HIGHApache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing PROT_P)EPSS 0.4%CVE-2024-25710HIGHApache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP fileEPSS 0.4%CVE-2025-66236HIGHApache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UIEPSS 0.4%CVE-2021-36151—Local Credentials Disclosure VulnerabilityEPSS 0.4%CVE-2026-86089LOWApache NiFi: Missing Process Group Authorization for Connector MigrationEPSS 0.4%CVE-2026-57914MEDIUMApache Kerby: StackOverflow on parsing deeply nested ASN1 structuresEPSS 0.4%CVE-2026-75157HIGHApache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDIT (asset-triggered scheduling suppression)EPSS 0.4%