Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-85229MEDIUMApache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)EPSS 0.3%CVE-2026-82382MEDIUMApache Roller: Reflected cross-site scripting in the frontpage directory parameterEPSS 0.3%CVE-2026-71378MEDIUMApache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationRequestCycleListenerEPSS 0.3%CVE-2024-45719LOWApache Answer: Predictable Authorization Token Using UUIDv1EPSS 0.2%CVE-2025-68637CRITICALApache Uniffle: Insecure SSL Configuration in Uniffle HTTP ClientEPSS 0.2%CVE-2024-23944MEDIUMApache ZooKeeper: Information disclosure in persistent watcher handlingEPSS 0.2%CVE-2025-54981HIGHApache StreamPark: Weak Encryption Algorithm in StreamParkEPSS 0.2%CVE-2025-66614HIGHApache Tomcat: Client certificate verification bypass due to virtual host mappingEPSS 0.2%CVE-2026-75973HIGHApache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configuredEPSS 0.2%CVE-2026-60093MEDIUMApache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDirEPSS 0.2%CVE-2025-55039MEDIUMApache Spark, Apache Spark: RPC encryption defaults to unauthenticated AES-CTR mode, enabling man-in-the-middle ciphertext modification attacksEPSS 0.2%CVE-2025-52435HIGHApache Mynewt NimBLE: Invalid error handling in pause encryption procedure in NimBLE controllerEPSS 0.2%CVE-2026-57590HIGHApache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unauthorized Cross-Project OperationsEPSS 0.2%CVE-2026-23901LOWApache Shiro: Brute force attack possible to determine valid user namesEPSS 0.2%CVE-2024-26307MEDIUMApache Doris: Possible race conditionEPSS 0.2%CVE-2026-71216MEDIUMApache SkyWalking: PagerDuty alarm hook transmits the integration routing key over cleartext HTTPEPSS 0.2%CVE-2026-82438HIGHApache Storm Webapp: Authenticated API Responses Exposed to Arbitrary Web OriginsEPSS 0.2%CVE-2026-91852MEDIUMApache Sling XSS: CWE-79 multiple raw-string break-outs and ReDOS in XSSImplEPSS 0.2%CVE-2026-27173HIGHApache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line ArgumentsEPSS 0.2%CVE-2026-68745HIGHApache CloudStack: SAML2 Signature Validation Silently Skipped for Cert-less IdPEPSS 0.2%