Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-50628CRITICALApache CXF: OAuth2: Inverted IP Binding Check Defeats Security ControlEPSS 1.0%CVE-2023-31007NONEApache Pulsar: Broker does not always disconnect client when authentication data expiresEPSS 1.0%CVE-2023-27523MEDIUMApache Superset: Improper data permission validation on Jinja templated queriesEPSS 1.0%CVE-2023-42505MEDIUMApache Superset: Sensitive information disclosure on db connection detailsEPSS 1.0%CVE-2026-58023MEDIUMApache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes pathEPSS 1.0%CVE-2024-36264CRITICALApache Submarine Commons Utils: default secretEPSS 1.0%CVE-2018-20245—The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and contained improper checEPSS 1.0%CVE-2026-80351CRITICALApache Camel K: Camel K Tenant repositories reach Maven execution inside operator podEPSS 1.0%CVE-2023-51785HIGHApache InLong: Arbitrary File Read Vulnerability in Apache InLong ManagerEPSS 1.0%CVE-2023-43668—Apache InLong: Jdbc Connection Security Bypass in InLongEPSS 1.0%CVE-2024-31863MEDIUMApache Zeppelin: Replacing other users notebook, bypassing any permissionsEPSS 1.0%CVE-2023-30575MEDIUMApache Guacamole: Incorrect calculation of Guacamole protocol element lengthsEPSS 1.0%CVE-2016-3083—Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). While validating the EPSS 1.0%CVE-2025-23048CRITICALApache HTTP Server: mod_ssl access control bypass with session resumptionEPSS 1.0%CVE-2023-43701MEDIUMApache Superset: Stored XSS on API endpointEPSS 1.0%CVE-2026-82310HIGHApache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT accessEPSS 1.0%CVE-2022-43721MEDIUMApache Superset: Open Redirect VulnerabilityEPSS 1.0%CVE-2026-43975MEDIUMApache Wicket: Possible malicious path traversal in FolderUploadsFileManagerEPSS 1.0%CVE-2025-23015HIGHApache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actionsEPSS 1.0%CVE-2025-67895CRITICALApache Airflow Providers Edge3: Edge3 Worker RPC RCE on Airflow 2EPSS 1.0%