Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-49298HIGHApache Airflow: JWT Token Exposure in KubernetesExecutor Command-Line ArgumentsEPSS 0.8%CVE-2026-61372HIGHApache Jena Fuseki: Web requests using SPARQL Update can escape file restrictionsEPSS 0.8%CVE-2026-63043HIGHApache InLong: Agent path traversal via unvalidated file source pathEPSS 0.8%CVE-2026-66907HIGHApache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the resultEPSS 0.8%CVE-2026-47896HIGHApache Lucene.Net: Unauthenticated arbitrary file read on the Lucene.Net.Replicator replication serverEPSS 0.8%CVE-2026-68979MEDIUMApache NiFi: Missing Authorization for Components Referenced by Parameter Context UpdatesEPSS 0.8%CVE-2026-61486CRITICALApache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed inputEPSS 0.8%CVE-2026-49875MEDIUMApache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointReferenceUtilsEPSS 0.8%CVE-2025-65082MEDIUMApache HTTP Server: CGI environment variable overrideEPSS 0.8%CVE-2026-61484CRITICALApache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoSEPSS 0.8%CVE-2025-25069MEDIUMApache Kvrocks: Cross-Protocol Scripting VulnerabilityEPSS 0.8%CVE-2026-64608CRITICALApache Fory: Heap type confusion and out-of-bounds read/write in C++ compatible-mode field-skip pathsEPSS 0.8%CVE-2026-44615MEDIUMPath traversal in NotebookRepo note and folder path compositionEPSS 0.8%CVE-2023-39441—Apache Airflow SMTP Provider, Apache Airflow IMAP Provider, Apache Airflow: SMTP/IMAP client components allowed MITM due to missing Certificate ValidationEPSS 0.8%CVE-2017-7666—Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.EPSS 0.8%CVE-2026-49363HIGHApache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE Protocol Topology SubscriptionEPSS 0.8%CVE-2026-45361HIGHApache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)EPSS 0.8%CVE-2026-42403HIGHApache Neethi: Circular Policy Reference Infinite LoopEPSS 0.8%CVE-2026-71559HIGHApache Fory: Uncaught panic (remote DoS) in Go meta-string decoder from untrusted metadataEPSS 0.8%CVE-2024-45626MEDIUMApache James: denial of service through JMAP HTML to text conversionEPSS 0.8%