Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2024-45384MEDIUMApache Druid: Padding oracle in druid-pac4j extension that allows an attacker to manipulate a pac4j session cookie via Padding Oracle AttackEPSS 0.8%CVE-2025-48913CRITICALApache CXF: Untrusted JMS configuration can lead to RCEEPSS 0.8%CVE-2026-49362HIGHApache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler Allows Unauthorized Queue CreationEPSS 0.8%CVE-2025-59775HIGHApache HTTP Server: NTLM Leakage on Windows through UNC SSRFEPSS 0.8%CVE-2025-22829LOWApache CloudStack: Unauthorised access to dedicated resources in Quota pluginEPSS 0.8%CVE-2026-45205MEDIUMApache Commons Configuration: StackOverflowError for YAML input with cyclesEPSS 0.8%CVE-2023-37579HIGHApache Pulsar Function Worker: Incorrect Authorization for Function Worker Can Leak Sink/Source CredentialsEPSS 0.8%CVE-2023-30428HIGHApache Pulsar Broker: Incorrect Authorization Validation for Rest ProducerEPSS 0.8%CVE-2026-41635CRITICALApache MINA: AbstractIoBuffer.resolveClass() null-clazz Branch Skips acceptMatchers Filter — Full Object Deserialization RCEEPSS 0.8%CVE-2026-48207CRITICALApache Fory: PyFory ReduceSerializer Incomplete Policy EnforcementEPSS 0.8%CVE-2024-56128MEDIUMApache Kafka: SCRAM authentication vulnerable to replay attacks when used without encryptionEPSS 0.8%CVE-2025-65995MEDIUMApache Airflow: Disclosure of secrets to UI via kwargsEPSS 0.8%CVE-2023-44312MEDIUMApache ServiceComb Service-Center: attacker can query all environment variables of the service-center serverEPSS 0.8%CVE-2024-55532CRITICALApache Ranger: Improper Neutralization of Formula Elements in a CSV FileEPSS 0.8%CVE-2026-49844MEDIUMApache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()EPSS 0.8%CVE-2023-27987CRITICALApache Linkis gateway module token authentication bypassEPSS 0.8%CVE-2026-76186CRITICALApache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identityEPSS 0.8%CVE-2026-86465MEDIUMApache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard bypass via user-controlled keyEPSS 0.8%CVE-2024-43204HIGHApache HTTP Server: SSRF with mod_headers setting Content-Type headerEPSS 0.8%CVE-2026-43869HIGHApache Thrift: TSSLTransportFactory.java hostname verificationEPSS 0.8%