Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2025-58457MEDIUMApache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore CommandsEPSS 0.3%CVE-2026-86350CRITICALApache Tomcat: Regression in fix for CVE-2026-41293 can trigger request header mix-upEPSS 0.3%CVE-2026-73191MEDIUMApache Syncope: CAS service URL injection via Forwarded HTTP headersEPSS 0.3%CVE-2026-56130LOWApache Shiro: Remember-me cookie isn't checked for expiry on the serverEPSS 0.3%CVE-2025-59792MEDIUMApache Kvrocks: MONITOR command reveals plaintext credentials to non-adminsEPSS 0.3%CVE-2026-82376HIGHApache Roller: XML external entity processing in trackback response parserEPSS 0.3%CVE-2026-49230MEDIUMApache APISIX: Authentication bypass in jwe-decryptEPSS 0.3%CVE-2024-29869MEDIUMApache Hive: Credentials file created with non restrictive permissionsEPSS 0.3%CVE-2026-44119MEDIUMApache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modulesEPSS 0.3%CVE-2026-66053MEDIUMApache Thrift: Python TSSLSocket Hostname Matcher ImportEPSS 0.3%CVE-2026-82386HIGHApache Roller: XML external entity processing in OPML bookmark importEPSS 0.3%CVE-2026-56624HIGHApache MINA SSHD: SSH certificate options lack validationsEPSS 0.3%CVE-2026-92573MEDIUMApache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON renderingEPSS 0.3%CVE-2026-40557MEDIUMApache Storm Prometheus Reporter: Disabling TLS verification for Prometheus Reporter also disables it for all other connectionsEPSS 0.3%CVE-2026-63687CRITICALApache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parametersEPSS 0.3%CVE-2024-29120MEDIUMApache StreamPark: Information leakage vulnerabilityEPSS 0.3%CVE-2026-65325MEDIUMApache Traffic Server: HTTP/2 multiplexed origin sessions are reused without certificate re-verificationEPSS 0.3%CVE-2024-27137MEDIUMApache Cassandra: unrestricted deserialization of JMX authentication credentialsEPSS 0.3%CVE-2026-44087MEDIUMApache APISIX: Openid-connect plugin Identity Header SpoofingEPSS 0.3%CVE-2026-82437MEDIUMApache Storm Logviewer: Log Access Controls Not Enforced by LogviewerEPSS 0.3%