Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-68763HIGHApache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is resetEPSS 0.9%CVE-2025-64401HIGHApache OpenOffice: Remote documents loaded without prompt via IFrameEPSS 0.9%CVE-2017-15703—Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and cauEPSS 0.9%CVE-2025-55668MEDIUMApache Tomcat: session fixation via rewrite valveEPSS 0.9%CVE-2023-42501MEDIUMApache Superset: Unnecessary read permissions within the Gamma roleEPSS 0.9%CVE-2026-67593CRITICALApache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-authentication Openwire protocol handling can result in queue deletionEPSS 0.9%CVE-2026-55993HIGHApache Camel Atmosphere Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling influencing internal behaviourEPSS 0.9%CVE-2026-46726HIGHApache Camel Vertx Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headersEPSS 0.9%CVE-2024-53948MEDIUMApache Superset: Error verbosity exposes metadata in analytics databasesEPSS 0.9%CVE-2026-66143HIGHApache Neethi: Missing global alternative-output budget across policy computation pathsEPSS 0.9%CVE-2026-84939CRITICALApache FreeMarker, Apache FreeMarker: A malformed locale may be exploitable for path traversal attacksEPSS 0.9%CVE-2026-34481MEDIUMApache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayoutEPSS 0.9%CVE-2024-56202MEDIUMApache Traffic Server: Expect header field can unreasonably retain resourceEPSS 0.9%CVE-2026-63317MEDIUMApache OpenNLP: Arbitrary Class Instantiation in GeneratorFactory via Feature Descriptor XMLEPSS 0.9%CVE-2023-30867—Apache StreamPark (incubating): Authenticated system users could trigger SQL injection vulnerabilityEPSS 0.9%CVE-2025-29847HIGHApache Linkis: Arbitrary File Read via Double URL Encoding BypassEPSS 0.9%CVE-2026-23904HIGHApache Kyuubi: Unrestricted access via Kyuubi engine-ui proxyEPSS 0.9%CVE-2024-45791HIGHApache HertzBeat: Exposure sensitive token via http GET method with query stringEPSS 0.8%CVE-2024-39676HIGHApache Pinot: Unauthorized endpoint exposed sensitive informationEPSS 0.8%CVE-2023-49566HIGHApache Linkis DataSource: JDBC Datasource Module with DB2 has JNDI Injection vulnerabilityEPSS 0.8%