Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2024-31979HIGHApache StreamPipes: Possibility of SSRF in pipeline element installation processEPSS 0.7%CVE-2026-78329CRITICALApache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routesEPSS 0.7%CVE-2026-41873CRITICALPony Mail: Admin account takeover via request smugglingEPSS 0.7%CVE-2026-56140CRITICALApache Camel AWS2 SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy to align it with sibling componentsEPSS 0.7%CVE-2026-71300CRITICALApache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injectionEPSS 0.7%CVE-2026-65637CRITICALApache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incompleteEPSS 0.7%CVE-2024-27182MEDIUMApache Linkis Basic management services: Engine material management Arbitrary file deletion vulnerabilityEPSS 0.7%CVE-2026-58065HIGHApache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verificationEPSS 0.7%CVE-2025-61581HIGHApache Traffic Control: ReDoS issue in Traffic Router configurationEPSS 0.7%CVE-2026-82355MEDIUMApache Airflow: Session cookie silently overrides explicit Authorization bearer header, enabling session fixationEPSS 0.7%CVE-2024-52067MEDIUMApache NiFi: Potential Insertion of Sensitive Parameter Values in Debug LogEPSS 0.7%CVE-2024-24779MEDIUMApache Superset: Improper data authorization when creating a new datasetEPSS 0.7%CVE-2026-48204CRITICALApache Camel: Camel-MongoDB-GridFS: The gridfs.* control headers used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to switch the GridFS operation - including destructive file deletion - in the default configurationEPSS 0.7%CVE-2026-57819HIGHApache CXF: No default restriction on the amount of form parameters per messageEPSS 0.7%CVE-2026-41636HIGHApache Thrift: Node.js skip() recursionEPSS 0.7%CVE-2026-54225HIGHApache CXF: Denial of Service attack via large attachmentsEPSS 0.7%CVE-2026-40920CRITICALApache Ranger: Privilege Escalation via URL ParameterEPSS 0.7%CVE-2026-22444HIGHApache Solr: Insufficient file-access checking in standalone core-creation requestsEPSS 0.7%CVE-2026-58182HIGHApache Traffic Server: ts_lua plugin has initialization and resource-handling errorsEPSS 0.7%CVE-2026-73634HIGHApache Struts: Unbounded read of a Content Security Policy violation reportEPSS 0.7%