Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2025-30067HIGHApache Kylin: The remote code execution via jdbc urlEPSS 0.9%CVE-2026-34479MEDIUMApache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden charactersEPSS 0.9%CVE-2026-46452MEDIUMApache NimBLE: Mesh Proxy SAR reassembly unbounded append and unchecked failureEPSS 0.9%CVE-2026-44417HIGHApache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE)EPSS 0.9%CVE-2023-50740MEDIUMApache Linkis DataSource: DataSource module Oracle SQL Database Password LoggedEPSS 0.9%CVE-2023-41314—Apache Doris: Missing API authentication allowed DoSEPSS 0.9%CVE-2026-49361HIGHApache Fluss Netty Frame Decoder Memory Exhaustion VulnerabilityEPSS 0.9%CVE-2024-26308MEDIUMApache Commons Compress: OutOfMemoryError unpacking broken Pack200 fileEPSS 0.9%CVE-2026-41607MEDIUMApache Thrift: C++ JSON OOB readEPSS 0.9%CVE-2024-26578MEDIUMApache Answer: Repeated submission at registration created duplicate users with the same nameEPSS 0.9%CVE-2025-27018MEDIUMApache Airflow MySQL Provider: SQL injection in MySQL provider core functionEPSS 0.9%CVE-2025-26866HIGHApache HugeGraph-Server: RAFT and deserialization vulnerabilityEPSS 0.9%CVE-2024-38311MEDIUMApache Traffic Server: Request smuggling via pipelining after a chunked message bodyEPSS 0.9%CVE-2023-49619LOWApache Answer: Repeated submissions using scripts resulted in an abnormal number of collections for questions.EPSS 0.9%CVE-2026-49845CRITICALApache Hive: SQL Injection vulnerability in HiveMetaStore partition-name direct-SQL pathsEPSS 0.9%CVE-2023-43826HIGHApache Guacamole: Integer overflow in handling of VNC image buffersEPSS 0.9%CVE-2024-23321HIGHApache RocketMQ: Unauthorized Exposure of Sensitive DataEPSS 0.9%CVE-2026-25747HIGHApache Camel LevelDB: Deserialization of Untrusted Data in Camel LevelDBEPSS 0.9%CVE-2024-39884MEDIUMApache HTTP Server: source code disclosure with handlers configured via AddTypeEPSS 0.9%CVE-2026-33558MEDIUMApache Kafka, Apache Kafka Clients: Information Exposure Through Network Client Log OutputEPSS 0.9%