Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2024-40761MEDIUMApache Answer: Avatar URL leaked user email addressesEPSS 0.7%CVE-2024-22369HIGHApache Camel: Camel-SQL: Unsafe Deserialization from JDBCAggregationRepositoryEPSS 0.7%CVE-2026-68968HIGHApache Airflow: Authorization bypass in the Backfill API through conflicting interpretations of the backfill idEPSS 0.7%CVE-2026-86473CRITICALApache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocable only by expiryEPSS 0.7%CVE-2026-58319CRITICALApache Doris: Improper Authentication in Frontend HTTP APIEPSS 0.7%CVE-2026-44631CRITICALApache HTTP Server: Heap Underflow in `ap_regname` via Signed Char OverflowEPSS 0.7%CVE-2026-53405CRITICALApache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTaskEPSS 0.7%CVE-2025-23195HIGHApache Ambari: XML External Entity (XXE) Vulnerability in Ambari/OozieEPSS 0.7%CVE-2026-66756MEDIUMApache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=falseEPSS 0.7%CVE-2026-41871CRITICALApache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)EPSS 0.7%CVE-2022-33684HIGHApache Pulsar C++/Python OAuth Clients prior to 3.0.0 were vulnerable to an MITM attack due to Disabled Certificate ValidationEPSS 0.7%CVE-2024-36265CRITICALApache Submarine Server Core: authorization bypassEPSS 0.7%CVE-2026-57821HIGHApache Fineract: Office list: SQL Injection via Subquery in orderByEPSS 0.7%CVE-2026-84439MEDIUMApache ZooKeeper: Audit log injection via unsanitized output from multiple sourcesEPSS 0.7%CVE-2024-45217HIGHApache Solr: ConfigSets created during a backup restore command are trusted implicitlyEPSS 0.7%CVE-2026-50076CRITICALApache Fory: Java ReplaceResolverSerializer deserialization checks bypassEPSS 0.7%CVE-2024-42516HIGHApache HTTP Server: HTTP response splittingEPSS 0.7%CVE-2025-49763HIGHApache Traffic Server: Remote DoS via memory exhaustion in ESI PluginEPSS 0.7%CVE-2025-55672MEDIUMApache Superset: Stored XSS on charts metadataEPSS 0.7%CVE-2026-84501MEDIUMApache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationProviderEPSS 0.7%