Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-49818MEDIUMApache Airflow Samba provider: Path traversal in GCSToSambaOperator via GCS object namesEPSS 1.0%CVE-2024-35161CRITICALApache Traffic Server: Incomplete check for chunked trailer section allows request smugglingEPSS 1.0%CVE-2023-46227HIGHApache inlong has an Arbitrary File Read VulnerabilityEPSS 1.0%CVE-2024-29217MEDIUMApache Answer: XSS vulnerability when changing personal websiteEPSS 1.0%CVE-2025-27821HIGHHDFS native client: Out of bounds write in URI parser of native HDFS clientEPSS 1.0%CVE-2024-36263HIGHApache Submarine Server Core: SQL injectionEPSS 1.0%CVE-2024-27438CRITICALApache Doris: Downloading arbitrary remote jar files resulting in remote command executionEPSS 1.0%CVE-2026-33929MEDIUMApache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example CodeEPSS 1.0%CVE-2022-47502—Apache OpenOffice: Macro URL arbitrary script executionEPSS 1.0%CVE-2023-25504MEDIUMApache Superset: Possible SSRF on import datasetsEPSS 1.0%CVE-2022-45786HIGHApache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injectionEPSS 1.0%CVE-2023-45757—Apache bRPC: The builtin service rpcz page has an XSS attack vulnerabilityEPSS 1.0%CVE-2024-45033HIGHApache Airflow Fab Provider: Application does not invalidate session after password change via Airflow cliEPSS 1.0%CVE-2024-52279HIGHApache Zeppelin: Arbitrary file read by adding malicious JDBC connection stringEPSS 1.0%CVE-2024-24772MEDIUMApache Superset: Improper Neutralisation of custom SQL on embedded contextEPSS 1.0%CVE-2026-34059HIGHApache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data()EPSS 1.0%CVE-2025-27820HIGHApache HttpComponents: PSL (Public Suffix List) validation bypassEPSS 0.9%CVE-2023-49734HIGHApache Superset: Privilege Escalation VulnerabilityEPSS 0.9%CVE-2026-29167CRITICALApache HTTP Server: mod_ldap per-dir use-after-freeEPSS 0.9%CVE-2026-42359HIGHApache Airflow: Authenticated RCE via XCom PATCH endpoint — XComUpdateBody missing FORBIDDEN_XCOM_KEYS validatorEPSS 0.9%