Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-59878HIGHApache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoSEPSS 0.8%CVE-2026-64606CRITICALApache Fory, Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interfaceEPSS 0.8%CVE-2026-69223CRITICALApache Allura: Server-side request forgeryEPSS 0.8%CVE-2025-66168MEDIUMApache ActiveMQ, Apache ActiveMQ All Module, Apache ActiveMQ MQTT Module: MQTT control packet remaining length field is not properly validatedEPSS 0.8%CVE-2026-48827HIGHApache MINA SSHD: Path traversal in org.apache.sshd:sshd-gitEPSS 0.8%CVE-2023-27525LOWApache Superset: Incorrect default permissions for Gamma roleEPSS 0.8%CVE-2024-24773MEDIUMApache Superset: Improper validation of SQL statements allows for unauthorized access to dataEPSS 0.8%CVE-2025-61623MEDIUMApache OFBiz: Reflected Cross-site ScriptingEPSS 0.8%CVE-2026-64609CRITICALApache Fory, Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deserializationEPSS 0.8%CVE-2026-50627CRITICALApache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token ValidatorEPSS 0.8%CVE-2026-66906CRITICALApache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDirEPSS 0.8%CVE-2026-65905CRITICALApache Tomcat: Limited replay attack possible with DIGEST authenticationEPSS 0.8%CVE-2026-55970MEDIUMApache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat()EPSS 0.8%CVE-2026-47430CRITICALCordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViewsEPSS 0.8%CVE-2026-67551HIGHApache Qpid Proton Dotnet: Type size/count handling can lead to excessive allocation pre-authenticationEPSS 0.8%CVE-2026-68060HIGHApache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authenticationEPSS 0.8%CVE-2026-66273HIGHApache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authenticationEPSS 0.8%CVE-2026-67552HIGHApache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stackoverflowEPSS 0.8%CVE-2026-67590HIGHApache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflowEPSS 0.8%CVE-2026-66274HIGHApache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflowEPSS 0.8%