Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-23983LOWApache Superset: Sensitive Data Exposure via REST API (disabled by default)EPSS 0.4%CVE-2026-61422MEDIUMApache CloudStack: Authenticated pre-validation SSRF in registerTemplateEPSS 0.4%CVE-2025-59790MEDIUMApache Kvrocks: RESET command grants admin privilegesEPSS 0.4%CVE-2024-23454MEDIUMApache Hadoop: Temporary File Local Information DisclosureEPSS 0.4%CVE-2025-62503MEDIUMApache Airflow: Privilege boundary bypass in bulk APIs (create action can upsert existing Pools/Connections/Variables)EPSS 0.4%CVE-2026-48144CRITICALApache Thrift: c_glib TLS Client Missing Hostname VerificationEPSS 0.4%CVE-2026-86243HIGHApache Tomcat Native: DoS via TLS handshakeEPSS 0.4%CVE-2026-54226MEDIUMApache Kvrocks: RESTORE IntSet Integer Overflow Leads to Remote DoSEPSS 0.4%CVE-2024-45462MEDIUMApache CloudStack: Incomplete session invalidation on web interface logoutEPSS 0.4%CVE-2025-62728MEDIUMApache Hive: SQL injection vulnerability when processing delete column statistics requests via the HMS Thrift APIsEPSS 0.4%CVE-2026-94301CRITICALApache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.X branches (2.0.30 / 2.1.14) ZDRES-232EPSS 0.4%CVE-2026-50631HIGHApache CXF: OAuth2: TOCTOU Race Condition in Refresh Token ProcessingEPSS 0.4%CVE-2026-77883MEDIUMApache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylistEPSS 0.4%CVE-2026-75015MEDIUMApache Syncope: Nested secrets leak cleartext into audit records readableEPSS 0.4%CVE-2025-58137HIGHApache Fineract: IDOR via self-service APIEPSS 0.4%CVE-2026-59244MEDIUMApache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UIEPSS 0.4%CVE-2026-76183CRITICALApache Tomcat: Bypass of security constraints for WebSocket endpointsEPSS 0.4%CVE-2026-68970MEDIUMApache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UIEPSS 0.4%CVE-2026-58156MEDIUMApache Traffic Server: URL and port parsing errors allow access-control bypassEPSS 0.4%CVE-2026-22922MEDIUMApache Airflow: Airflow externalLogUrl Permission BypassEPSS 0.4%