Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-44613MEDIUMApache Zeppelin: Cross-site request forgery in REST and WebSocket request handlingEPSS 0.4%CVE-2026-86248CRITICALApache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabledEPSS 0.4%CVE-2026-45760HIGHApache Camel K: Camel K Cross-Namespace Build Deputy AttackEPSS 0.4%CVE-2026-82431CRITICALApache Storm Client: Authorization Bypass When nimbus.groups Is Configured Without nimbus.usersEPSS 0.4%CVE-2023-51702MEDIUMApache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer serviceEPSS 0.4%CVE-2024-39954MEDIUMApache EventMesh Runtime: SSRFEPSS 0.4%CVE-2026-68570MEDIUMApache Doris: Authorization bypass leading to unauthorized data accessEPSS 0.4%CVE-2025-62235HIGHApache Mynewt NimBLE: Incorrect handling of SMP Security Request could lead to undesirable pairingEPSS 0.4%CVE-2025-49506HIGHApache Portable Runtime Utility: apr_password_validate() vulnerable to timing attackEPSS 0.4%CVE-2026-75156CRITICALApache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated — cross-tenant authentication bypassEPSS 0.4%CVE-2026-43870HIGHApache Thrift: Node.js web_server.js multi-vulnerabilityEPSS 0.4%CVE-2026-92609CRITICALApache Qpid Broker-J: Missing HTTP-session renewal after successful authenticationEPSS 0.4%CVE-2026-78383HIGHApache Tomcat: AJP DoS via missing request bodyEPSS 0.4%CVE-2026-41017MEDIUMApache Airflow: JWT cookie missing Secure flag in JWTRefreshMiddleware behind HTTPS-terminating proxyEPSS 0.4%CVE-2026-73631MEDIUMApache Struts: Shared parsing state in the JSON pluginEPSS 0.4%CVE-2026-73632MEDIUMApache Struts: Shared serialization state in the JSON pluginEPSS 0.4%CVE-2026-97636MEDIUMApache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled keyEPSS 0.4%CVE-2025-66467HIGHApache CloudStack: MinIO policy remains intact on bucket deletionEPSS 0.4%CVE-2026-82432HIGHApache Storm Nimbus: Blobstore Authorization Bypass via Rebalance Configuration OverridesEPSS 0.4%CVE-2026-59083CRITICALApache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypassEPSS 0.4%