Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-33454CRITICALApache Camel: Inbound Header Filter Missing in MailHeaderFilterStrategy Allows Remote Code Execution via MIME Header Injection (CVE-2025-30177 Variant)EPSS 1.0%CVE-2026-40022HIGHApache Camel Platform HTTP Main: Authentication Bypass on Non-Root Context Paths in camel main runtimeEPSS 1.0%CVE-2023-49920—Apache Airflow: Missing CSRF protection on DAG/triggerEPSS 1.0%CVE-2026-48586HIGHApache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression Size LimitEPSS 1.0%CVE-2026-43871HIGHApache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limitEPSS 1.0%CVE-2026-58389HIGHApache Thrift: Rust binary protocol non-strict path missing string size limitEPSS 1.0%CVE-2026-61483HIGHApache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow DoSEPSS 1.0%CVE-2026-55969HIGHApache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()EPSS 1.0%CVE-2026-49158HIGHApache Thrift: Ruby THeaderTransport ZLIB Decompression BombEPSS 1.0%CVE-2026-45112MEDIUMApache Thrift: Unbounded Read Leading to Denial of ServiceEPSS 1.0%CVE-2026-45816HIGHApache NimBLE: NULL pointer dereference vulnerability in SMP LTK requestEPSS 1.0%CVE-2025-27819HIGHApache Kafka: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configurationEPSS 1.0%CVE-2026-45815HIGHApache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handlerEPSS 1.0%CVE-2026-41608HIGHApache Thrift: Unbounded Zlib Decompression in Python THeaderTransportEPSS 1.0%CVE-2026-55968HIGHApache Thrift: Node.js quadratic-time DoS in server receive transportsEPSS 1.0%CVE-2024-29736HIGHApache CXF: SSRF vulnerability via WADL stylesheet parameterEPSS 1.0%CVE-2020-17521—Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extEPSS 1.0%CVE-2023-35908—Apache Airflow: Access to DAGs without relevant permissionEPSS 1.0%CVE-2018-11790—When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, the defeEPSS 1.0%CVE-2024-27349CRITICALApache HugeGraph-Server: Bypass whitelist in Auth modeEPSS 1.0%