Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-58163HIGHApache Traffic Server: Cache deserialization and lifetime errors can corrupt state or crash the serverEPSS 0.7%CVE-2026-73635HIGHApache Struts: Unbounded growth of localized-text caches driven by the request localeEPSS 0.7%CVE-2026-73633HIGHApache Struts: Unbounded read of a JSON request bodyEPSS 0.7%CVE-2026-65017MEDIUMApache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi-team masking bypass)EPSS 0.7%CVE-2026-31379MEDIUMApache OFBiz: Path Traversal and File Upload Validation Bypass Leading to Arbitrary File Write, Stored XSS and RCE in Catalog ManagerEPSS 0.7%CVE-2025-69219HIGHApache Airflow Providers Http: Unsafe Pickle Deserialization in apache-airflow-providers-http leading to RCE via HttpOperatorEPSS 0.7%CVE-2026-55956MEDIUMApache Tomcat: Security constraints for default servlet ignored methodEPSS 0.7%CVE-2024-22371LOWApache Camel issue on ExchangeCreatedEventEPSS 0.7%CVE-2025-55674MEDIUMApache Superset: Improper SQL authorisation, parse not checking for specific engine functionsEPSS 0.7%CVE-2026-45812MEDIUMApache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report HandlerEPSS 0.7%CVE-2025-25247MEDIUMApache Felix Webconsole: XSS in services consoleEPSS 0.7%CVE-2026-82428HIGHApache Storm Client: Cross-Tenant Dependency Jar Substitution via Predictable Blob KeysEPSS 0.7%CVE-2026-46587HIGHApache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted inputEPSS 0.7%CVE-2016-5001—This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HEPSS 0.7%CVE-2026-46588HIGHApache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted inputEPSS 0.7%CVE-2024-38379MEDIUMApache Allura: Stored authenticated XSSEPSS 0.7%CVE-2026-57817HIGHApache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flowEPSS 0.7%CVE-2022-23181—Local privilege escalation with FileStoreEPSS 0.7%CVE-2024-24778MEDIUMApache StreamPipes: Resources Permission EscalationEPSS 0.7%CVE-2022-33681MEDIUMImproper Hostname Verification in Java Client and Proxy can expose authentication data via MITMEPSS 0.7%