Vulnerabilidades em Apache Software Foundation

2.396 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-23985MEDIUMApache Superset: Regular Expression Denial of Service (ReDoS) in SQL ParserEPSS 0.7%CVE-2025-26865LOWApache OFBiz: Server-Side Template Injection affecting the ecommerce plugin leading to possible RCEEPSS 0.7%CVE-2026-82435CRITICALApache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker Messaging DecoderEPSS 0.7%CVE-2026-65432HIGHApache CXF: XXE via WSDL/XSD import parsingEPSS 0.7%CVE-2026-53404HIGHApache Tomcat: Bad ornext processing in RewriteValveEPSS 0.7%CVE-2025-66200MEDIUMApache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfoEPSS 0.7%CVE-2024-53868HIGHApache Traffic Server: Malformed chunked message body allows request smugglingEPSS 0.6%CVE-2026-45187MEDIUMApache OFBiz: Improper Authorization in Scheduled Job Creation Allows Low-Privileged Users to Submit System JobsEPSS 0.6%CVE-2026-33005MEDIUMApache OpenMeetings: Insufficient checks in FileWebServiceEPSS 0.6%CVE-2025-26521HIGHApache CloudStack: CKS cluster in project exposes user API keysEPSS 0.6%CVE-2026-35554HIGHApache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race ConditionEPSS 0.6%CVE-2026-44913MEDIUMApache NiFi: Improper Escaping of Table Names in CaptureChangeMySQLEPSS 0.6%CVE-2026-42498HIGHApache Tomcat: WebSocket authentication header exposureEPSS 0.6%CVE-2026-48895LOWApache APISIX: Cas-auth Host header influence on CAS service URLEPSS 0.6%CVE-2026-23980MEDIUMApache Superset: Improper Neutralization of Special Elements used in a SQL CommandEPSS 0.6%CVE-2024-27181HIGHApache Linkis Basic management services: Privilege Escalation Attack vulnerabilityEPSS 0.6%CVE-2026-63040HIGHApache InLong: Missing authorization in StreamSource forceDeleteEPSS 0.6%CVE-2026-63042HIGHApache InLong: Missing authorization on DataNode management endpointsEPSS 0.6%CVE-2026-59243CRITICALApache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)EPSS 0.6%CVE-2026-44915LOWApache APISIX: Cas-auth plugin open redirect via unsanitized cookie valueEPSS 0.6%