Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-49042HIGHApache Camel: langchain4j-tools: filter tool argument headers against declared parametersEPSS 0.7%CVE-2024-47250MEDIUMApache NimBLE: Lack of input validation in HCI advertising report could lead to potential out-of-bound accessEPSS 0.7%CVE-2026-62183CRITICALApache Syncope: User self-service privilege escalationEPSS 0.7%CVE-2026-28812CRITICALApache JSPWiki: UserManager does not sanity-check user database at startupEPSS 0.7%CVE-2026-46455CRITICALApache Camel: Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be acceptedEPSS 0.7%CVE-2026-34884CRITICALApache SkyWalking MCP: SSRF via set_skywalking_url Tool and GraphQL Expression Injection in MCP ServerEPSS 0.7%CVE-2026-24014CRITICALApache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File WriteEPSS 0.7%CVE-2024-44088MEDIUMApache Geode: Reflected XSSEPSS 0.7%CVE-2026-47341MEDIUMApache APISIX: Session replay issue in hmac-authEPSS 0.7%CVE-2026-46718MEDIUMApache Calcite: A user-controled model can load arbitrary classes, leading to code executionEPSS 0.7%CVE-2026-42810CRITICALApache Polaris: could broaden vended S3 credentials through wildcard-bearing namespace or table namesEPSS 0.7%CVE-2026-63037CRITICALApache InLong: Unauthenticated SQL injection in Manager OpenAPI audit alert rule list endpointEPSS 0.7%CVE-2026-62390CRITICALApache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh APIEPSS 0.7%CVE-2026-32227CRITICALApache Ranger: SQL Injection vulnerability in lookup functionalityEPSS 0.7%CVE-2026-63038CRITICALApache InLong: SQL Injection via String Concatenation Vulnerability ReportEPSS 0.7%CVE-2026-63039CRITICALApache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleServiceEPSS 0.7%CVE-2026-50750HIGHApache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire DoS following fix for CVE-2026-49270EPSS 0.7%CVE-2025-66169MEDIUMApache Camel Neo4j: Cypher injection vulnerability in Camel-Neo4j componentEPSS 0.7%CVE-2026-60080HIGHApache Fory: Rust MetaString heap use-after-freeEPSS 0.7%CVE-2026-24880HIGHApache Tomcat: Request smuggling via invalid chunk extensionEPSS 0.7%