Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-27314HIGHApache Cassandra: Privilege escalation via ADD IDENTITY authorization bypassEPSS 0.3%CVE-2026-53561HIGHApache Hive: Unauthenticated authentication bypass in HiveServer2 HTTP SAML bearer-token validation allows impersonation of any Hive userEPSS 0.3%CVE-2026-82433MEDIUMApache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Daemon Configuration via Nimbus and the UIEPSS 0.3%CVE-2026-82439CRITICALApache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPCEPSS 0.3%CVE-2025-53470LOWApache Mynewt NimBLE: Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driverEPSS 0.3%CVE-2026-59657HIGHApache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJobEPSS 0.3%CVE-2026-96443MEDIUMApache Doris: JDBC driver URL validation bypass leads to remote code executionEPSS 0.3%CVE-2023-49582MEDIUMApache Portable Runtime (APR): Unexpected lax shared memory permissionsEPSS 0.3%CVE-2026-43828MEDIUMApache Shiro: Shiro's native session and rememberMe cookies do not have secure flag set by defaultEPSS 0.3%CVE-2026-71290CRITICALApache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)EPSS 0.3%CVE-2025-59060MEDIUMApache Ranger: Hostname verification bypass in NiFiRegistryClientEPSS 0.3%CVE-2026-59969HIGHApache ZooKeeper: Improper validation of certificate with host mismatch in FIPS modeEPSS 0.3%CVE-2024-46544MEDIUMApache Tomcat Connectors: mod_jk: local users can view and modify configurationEPSS 0.3%CVE-2026-54665MEDIUMApache NiFi: Missing Validation for Proxy Host HeadersEPSS 0.3%CVE-2026-46751MEDIUMApache Kvrocks: Does not remove the unsafe loadstring function from its Lua sandbox, allowing a user who can run EVAL scripts to load crafted, unvalidated bytecode that crashes the server process, resulting in a remote denial of service.EPSS 0.3%CVE-2024-45627MEDIUMApache Linkis Metadata Query Service JDBC: JDBC Datasource Module with Mysql has file read vulnerabilityEPSS 0.3%CVE-2017-3166—In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that makEPSS 0.3%CVE-2026-92608HIGHApache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10EPSS 0.3%CVE-2026-79677HIGHApache Tomcat: WebSocket DoS due to lost asynchronous write timeoutEPSS 0.3%CVE-2024-25142MEDIUMApache Airflow: Cache Control - Storage of Sensitive Data in Browser Cache EPSS 0.3%