Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2025-47868CRITICALApache NuttX RTOS: tools/bdf-converter.: tools/bdf-converter: Fix loop termination condition.EPSS 0.7%CVE-2025-47869CRITICALApache NuttX RTOS: examples/xmlrpc: Fix calls buffers size.EPSS 0.7%CVE-2026-24012HIGHApache IoTDB: Denial of Service via Resource Exhaustion in Aggregation QueryEPSS 0.7%CVE-2026-59173HIGHApache Traffic Server: DoS vulnerability in HTTP/2 via stalled flow-control conditionsEPSS 0.7%CVE-2026-91866HIGHApache Neethi: Crafted policies cause unbounded work during intersection leading to denial of serviceEPSS 0.7%CVE-2026-67211HIGHApache OpenNLP: OOM DoS via Unbounded Array Allocation in SymSpellModelSerializerEPSS 0.7%CVE-2026-68981HIGHApache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP RequestsEPSS 0.7%CVE-2026-66144HIGHApache Neethi: Remote PolicyReference fetch lacks resource boundsEPSS 0.7%CVE-2026-66299HIGHApache Tomcat: DoS via WebSocket chat exampleEPSS 0.7%CVE-2026-66142HIGHApache Neethi: Uncontrolled recursion in policy processingEPSS 0.7%CVE-2026-53916HIGHApache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codecEPSS 0.7%CVE-2026-67592HIGHApache Qpid ProtonJ2: Unable to govern the maximum number of transfer frames per incoming deliveryEPSS 0.7%CVE-2026-71257HIGHApache Wicket: Configured file upload limits are not enforced when the multipart request has already been parsedEPSS 0.7%CVE-2026-42402HIGHApache Neethi: Policy Normalization Unbounded Resource Allocation DoSEPSS 0.7%CVE-2026-91864HIGHApache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustionEPSS 0.7%CVE-2026-91865HIGHApache Neethi: Crafted policy references cause exponential expansion during normalization leading to denial of serviceEPSS 0.7%CVE-2026-53917HIGHApache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: Unbounded memory allocation in OpenWire property unmarshallingEPSS 0.7%CVE-2026-50645HIGHApache CXF: No restriction on attachment headers per messageEPSS 0.7%CVE-2026-75005HIGHApache APISIX: Unauthenticated CPU-exhaustion DoSEPSS 0.7%CVE-2026-50734HIGHApache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire memory-allocation DoS during wire format negotiationEPSS 0.7%