Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2025-49124HIGHApache Tomcat: exe side-loading via icalcs.exe in Tomcat installer for WindowsEPSS 0.4%CVE-2026-23984HIGHApache Superset: SQLLab Read-Only Bypass on PostgreSQLEPSS 0.4%CVE-2026-77762HIGHApache Tomcat: Stale HPACK emitter injects trailers into recycled pooled RequestEPSS 0.4%CVE-2026-73334HIGHApache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that skips host validationEPSS 0.4%CVE-2025-59454MEDIUMApache CloudStack: Lack of user permission validation leading to data leak for few APIsEPSS 0.4%CVE-2022-45935MEDIUMApache James server: Temporary File Information DisclosureEPSS 0.4%CVE-2026-73236HIGHApache Syncope: Cross-Realm authorization bypass in delegated administrationEPSS 0.4%CVE-2026-50634MEDIUMApache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entryEPSS 0.4%CVE-2026-40948MEDIUMApache Airflow Providers Keycloak: OAuth Login CSRF — Missing State Parameter in Keycloak Auth ManagerEPSS 0.4%CVE-2026-58162HIGHApache Traffic Server: Certifier plugin trusts client SNI when generating certificatesEPSS 0.4%CVE-2025-47410HIGHApache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh commands on the target systemEPSS 0.4%CVE-2026-23903MEDIUMApache Shiro: Auth bypass when accessing static files only on case-insensitive filesystemsEPSS 0.4%CVE-2026-40009MEDIUMApache IoTDB: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditorEPSS 0.4%CVE-2023-43123—Apache Storm: Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary filesEPSS 0.4%CVE-2026-49871LOWApache APISIX: cas-auth login CSRF / session injection issueEPSS 0.4%CVE-2026-57111HIGHApache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-OriginEPSS 0.3%CVE-2025-58337MEDIUMApache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode for doris-mcp-server MCP ServerEPSS 0.3%CVE-2024-27906MEDIUMApache Airflow: Dag Code and Import Error Permissions IgnoredEPSS 0.3%CVE-2026-33266HIGHApache OpenMeetings: Hardcoded Remember-Me Cookie Encryption Key and SaltEPSS 0.3%CVE-2023-30601HIGHApache Cassandra: Privilege escalation when enabling FQL/Audit logsEPSS 0.3%