Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2018-1286—In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to dEPSS 1.1%CVE-2026-53913CRITICALApache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default configuration the token is never verified and any non-null bearer value is acceptedEPSS 1.1%CVE-2024-35296HIGHApache Traffic Server: Invalid Accept-Encoding can force forwarding requestsEPSS 1.1%CVE-2025-48431HIGHApache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error.EPSS 1.1%CVE-2022-40743MEDIUMApache Traffic Server: Security issues with the xdebug pluginEPSS 1.1%CVE-2026-58662HIGHApache Thrift: C++ THeaderTransport::readString() info-header length bounds bypassEPSS 1.1%CVE-2024-23349MEDIUMApache Answer: XSS vulnerability when submitting summaryEPSS 1.1%CVE-2026-57967CRITICALApache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session reattachmentEPSS 1.1%CVE-2023-42780—Apache Airflow: Improper access control vulnerability in the "List dag warnings" featureEPSS 1.1%CVE-2026-29168HIGHApache HTTP Server: mod_md unrestricted OCSP responseEPSS 1.1%CVE-2026-48913HIGHApache HTTP Server: mod_http2 memory corruption when file handles exhaustedEPSS 1.1%CVE-2026-39304HIGHApache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOMEPSS 1.1%CVE-2026-42440HIGHApache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReaderEPSS 1.1%CVE-2024-32638MEDIUMApache APISIX: Forward-Auth Request SmugglingEPSS 1.1%CVE-2023-50379HIGHApache Ambari: authenticated users could perform command injection to perform RCEEPSS 1.1%CVE-2024-56373HIGHApache Airflow: SSTI to Code Execution in Airflow through Shared DB InformationEPSS 1.1%CVE-2026-44186HIGHApache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftpEPSS 1.1%CVE-2025-66518HIGHApache Kyuubi: Unauthorized directory access due to missing path normalizationEPSS 1.1%CVE-2024-31869MEDIUMApache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config usedEPSS 1.1%CVE-2026-33858HIGHApache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom APIEPSS 1.1%