Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-56091HIGHApache Shiro: Authentication bypass in Guice-Web integrationEPSS 0.7%CVE-2026-42527HIGHApache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosureEPSS 0.7%CVE-2024-45031MEDIUMApache Syncope: Stored XSS in Console and EnduserEPSS 0.7%CVE-2026-31378MEDIUMApache OFBiz: JSON Attribute Override and URL Allowlist Bypass Leads to Remote Code ExecutionEPSS 0.7%CVE-2024-23590CRITICALApache Kylin: Session fixation in web interfaceEPSS 0.7%CVE-2025-57735CRITICALApache Airflow: Airflow Logout Not Invalidating JWTEPSS 0.7%CVE-2026-41870HIGHApache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)EPSS 0.7%CVE-2026-58180HIGHApache Traffic Server: txn_box plugin overflows the stack from attacker inputEPSS 0.7%CVE-2026-48828MEDIUMApache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the keyEPSS 0.7%CVE-2026-45192MEDIUMApache Airflow: Incomplete Redaction of Sensitive Fields in Connection Extra API ResponseEPSS 0.7%CVE-2026-64958HIGHApache CXF: Denial of service via message header attachmentsEPSS 0.7%CVE-2026-58161CRITICALApache Traffic Server: Memory-safety errors in TLS and SNI handling can crash the serverEPSS 0.7%CVE-2026-58178HIGHApache Traffic Server: ESI plugin allows uncontrolled recursion and server-side request forgeryEPSS 0.7%CVE-2026-43826MEDIUMApache Airflow Providers OpenSearch: OpenSearch task-log handler leaks credentials embedded in the host URLEPSS 0.7%CVE-2026-48892MEDIUMApache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic optionsEPSS 0.7%CVE-2026-68481HIGHApache CXF: Revocation bypass in DefaultEncryptingOAuthDataProviderEPSS 0.7%CVE-2026-58164HIGHApache Traffic Server: Remap configuration lifetime and TOCTOU errors cause use-after-freeEPSS 0.7%CVE-2026-58181HIGHApache Traffic Server: uri_signing and url_sig plugins can exhaust the stack or crashEPSS 0.7%CVE-2026-49487MEDIUMApache Airflow: Task-instance API exposes secrets in deferred trigger kwargsEPSS 0.7%CVE-2026-58151HIGHApache Traffic Server: Abusive HTTP/2 framing can exhaust resources and crash the serverEPSS 0.7%