Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2025-53477HIGHApache Mynewt NimBLE: NULL Pointer Dereference in NimBLE host HCI layerEPSS 0.8%CVE-2025-27526MEDIUMApache InLong: JDBC Vulnerability For URLEncode and backspace bypassEPSS 0.8%CVE-2026-59242MEDIUMApache Airflow: Arbitrary airflow.* class instantiation on the API server via the XCom deserialize endpointEPSS 0.8%CVE-2026-29220MEDIUMApache OFBiz: Low-Privilege LFI in Content ComponentEPSS 0.8%CVE-2026-73237MEDIUMApache Allura: XSS in markdown pipelineEPSS 0.8%CVE-2026-73238MEDIUMApache Allura: XSS in code displayEPSS 0.8%CVE-2023-39196MEDIUMApache Ozone: Missing mutual TLS authentication in one of the service internal Ozone Storage Container Manager endpointsEPSS 0.8%CVE-2021-33900—StartTLS and SASL confidentiality protection bypassEPSS 0.8%CVE-2026-46456CRITICALApache Camel: Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headersEPSS 0.8%CVE-2026-87976HIGHApache NiFi Registry: Improper Limitation of Pathname in Persisted Extension BundlesEPSS 0.8%CVE-2026-34538MEDIUMApache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure)EPSS 0.8%CVE-2026-34020HIGHApache OpenMeetings: Login Credentials Passed via GET Query ParametersEPSS 0.8%CVE-2026-62764MEDIUMApache Accumulo: A user can trigger a graceful shutdown of services without the relevant system permissionsEPSS 0.8%CVE-2026-28811HIGHApache JSPWiki: Error Handling - Reveals Error DetailsEPSS 0.8%CVE-2024-29070CRITICALApache StreamPark: session not invalidated after logoutEPSS 0.8%CVE-2025-24783HIGHApache Cocoon: continuations may not be privateEPSS 0.8%CVE-2026-62391HIGHApache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliasesEPSS 0.8%CVE-2024-56180CRITICALApache EventMesh: raft Hessian Deserialization Vulnerability allowing remote code executionEPSS 0.8%CVE-2024-29007HIGHApache CloudStack: When downloading templates or ISOs, the management server and SSVM follow HTTP redirects with potentially dangerous consequencesEPSS 0.8%CVE-2026-49432HIGHApache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative content-length enables denial of serviceEPSS 0.8%