Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-41017MEDIUMApache Airflow: JWT cookie missing Secure flag in JWTRefreshMiddleware behind HTTPS-terminating proxyEPSS 0.4%CVE-2026-73631MEDIUMApache Struts: Shared parsing state in the JSON pluginEPSS 0.4%CVE-2026-73632MEDIUMApache Struts: Shared serialization state in the JSON pluginEPSS 0.4%CVE-2026-97636MEDIUMApache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled keyEPSS 0.4%CVE-2026-82375HIGHApache Roller: Server-side request forgery via entry trackback and enclosure URLsEPSS 0.4%CVE-2025-66467HIGHApache CloudStack: MinIO policy remains intact on bucket deletionEPSS 0.4%CVE-2026-82432HIGHApache Storm Nimbus: Blobstore Authorization Bypass via Rebalance Configuration OverridesEPSS 0.4%CVE-2026-59083CRITICALApache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypassEPSS 0.4%CVE-2026-82379HIGHApache Roller: WSSE digest authentication headers can be replayedEPSS 0.4%CVE-2025-27555MEDIUMApache Airflow: Connection Secrets not masked in UI when Connection are added via Airflow cliEPSS 0.4%CVE-2026-31923HIGHApache APISIX: Openid-connect `tls_verify` field is disabled by defaultEPSS 0.4%CVE-2026-29129HIGHApache Tomcat: TLS cipher order is not preservedEPSS 0.4%CVE-2026-92550HIGHApache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoderEPSS 0.4%CVE-2026-73195HIGHApache Syncope: CSV export spreadsheet formula injectionEPSS 0.4%CVE-2026-92560HIGHApache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoderEPSS 0.4%CVE-2026-86466HIGHApache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validatedEPSS 0.4%CVE-2026-82348HIGHApache Roller: Cross-weblog resource tampering via unscoped authoring lookupsEPSS 0.4%CVE-2026-31924MEDIUMApache APISIX: Plugin tencent-cloud-cls log export uses plaintext HTTPEPSS 0.4%CVE-2026-41566CRITICALApache Kvrocks: Improper permission for the APPLYBATCH commandEPSS 0.4%CVE-2026-68870MEDIUMApache Airflow Microsoft Azure provider: microsoft.azure Key Vault backend: team-scope guard bypass resolves another team's Connection or VariableEPSS 0.4%