Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-40682CRITICALApache OpenNLP: XXE via Dictionary Parsing in DictionaryEntryPersistorEPSS 0.8%CVE-2024-31391MEDIUMApache Solr Operator: Solr-Operator liveness and readiness probes may leak basic auth credentialsEPSS 0.8%CVE-2025-48768MEDIUMApache NuttX RTOS: fs/inode: fs_inoderemove root inode removalEPSS 0.8%CVE-2024-47197HIGHMaven Archetype Plugin: Maven Archetype integration-test may package local settings into the published artifact, possibly containing credentialsEPSS 0.8%CVE-2026-46590HIGHApache Camel: Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048)EPSS 0.8%CVE-2023-25753—Server-Side Request Forgery in Apache ShenYuEPSS 0.8%CVE-2026-44617MEDIUMApache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867EPSS 0.8%CVE-2023-49657CRITICALApache Superset: Stored XSS in Dashboard Title and Chart TitleEPSS 0.8%CVE-2025-27522MEDIUMApache InLong: JDBC Vulnerability during verification processingEPSS 0.8%CVE-2026-80352CRITICALApache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objectsEPSS 0.8%CVE-2024-53947LOWApache Superset: Improper SQL authorisation, parse not checking for specific postgres functionsEPSS 0.8%CVE-2026-31987HIGHApache Airflow: JWT token appearing in logsEPSS 0.8%CVE-2026-57308CRITICALApache Syncope: SQL injection vulnerability in Audit Events searchEPSS 0.8%CVE-2023-42502MEDIUMApache Superset: Open Redirect VulnerabilityEPSS 0.8%CVE-2026-86462CRITICALApache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessionsEPSS 0.8%CVE-2018-1325—In Apache wicket-jquery-ui <= 6.29.0, <= 7.10.1, <= 8.0.0-M9.1, JS code created in WYSIWYG editor will be executed on display.EPSS 0.8%CVE-2026-46454CRITICALApache Camel: Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrategy, allowing unauthenticated clients to inject Camel control headersEPSS 0.8%CVE-2024-38479HIGHApache Traffic Server: Cache key plugin is vulnerable to cache poisoning attackEPSS 0.8%CVE-2016-6806—Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin rEPSS 0.8%CVE-2026-25087HIGHApache Arrow: Potential use-after-free when reading IPC file with pre-bufferingEPSS 0.8%