Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-58175HIGHApache Traffic Server: HostDB SRV handling leaks memoryEPSS 0.7%CVE-2026-41018MEDIUMApache Airflow Providers Elasticsearch: Elasticsearch task-log handler leaks credentials embedded in the host URLEPSS 0.7%CVE-2026-65324HIGHApache Traffic Server: HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowing memory exhaustionEPSS 0.7%CVE-2025-50213CRITICALApache Airflow Providers Snowflake: Potential SQL injection in CopyFromExternalStageToSnowflakeOperatorEPSS 0.7%CVE-2026-24713CRITICALApache IoTDB: JEXL Expression Injection VulnerabilityEPSS 0.7%CVE-2026-58183HIGHApache Traffic Server: prefetch plugin can crash on attacker-influenced inputEPSS 0.7%CVE-2026-44914HIGHApache NiFi: Missing Authorization of Restricted Permissions when Replacing Flow ContentsEPSS 0.7%CVE-2024-30471MEDIUMApache StreamPipes: Potential creation of multiple identical accountsEPSS 0.7%CVE-2026-46457HIGHApache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headersEPSS 0.7%CVE-2026-28814HIGHApache JSPWiki: Pre-Authentication Arbitrary Wiki Markup RenderingEPSS 0.7%CVE-2026-55814HIGHApache Ranger: Download APIs expose plugin data without authenticationEPSS 0.7%CVE-2026-32690LOWApache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1EPSS 0.7%CVE-2025-27531CRITICALApache InLong: An arbitrary file read vulnerability for JDBCEPSS 0.7%CVE-2026-42588HIGHApache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnectorEPSS 0.7%CVE-2026-35194HIGHApache Flink: Remote code execution via SQL injection in code generationEPSS 0.7%CVE-2025-48795MEDIUMApache CXF: Denial of Service and sensitive data exposure in logsEPSS 0.7%CVE-2025-68438HIGHApache Airflow: Secrets in rendered templates could contain parts of sensitive values when truncatedEPSS 0.7%CVE-2025-66335MEDIUMApache Doris MCP Server: MCP SQL injectEPSS 0.7%CVE-2026-32966HIGHApache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata DisclosureEPSS 0.7%CVE-2026-43866HIGHApache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolderEPSS 0.7%