Vulnerabilidades em Apache Software Foundation

2.396 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-68969MEDIUMApache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartextEPSS 0.6%CVE-2026-78330CRITICALApache Syncope: Privilege escalation for admin user via JWT authenticationEPSS 0.6%CVE-2024-45479CRITICALApache Ranger: SSRF in Edit Service page - Add logic to filter requests to localhostEPSS 0.6%CVE-2026-58153MEDIUMApache Traffic Server: HTTP/2 to HTTP/1 conversion forwards origin trailers to clients unsafelyEPSS 0.6%CVE-2023-52290HIGHApache StreamPark (incubating): Unchecked SQL query fields trigger SQL injection vulnerabilityEPSS 0.6%CVE-2026-70410HIGHApache Calcite Avatica: Unrestricted class initialization when instantiating pluginsEPSS 0.6%CVE-2025-59328MEDIUMApache Fory: Denial of Service (DoS) due to Deserialization of Untrusted malicious large DataEPSS 0.6%CVE-2026-34031MEDIUMApache Answer: The custom avatar was not properly validatedEPSS 0.6%CVE-2026-50630MEDIUMApache CXF: OAuth2: HTTP Response Splitting via WWW-Authenticate Realm InjectionEPSS 0.6%CVE-2026-66391MEDIUMApache Wicket: leaked and missing CSP headersEPSS 0.6%CVE-2026-65945MEDIUMApache Ranger: Logs contain replayable JWT bearer tokensEPSS 0.6%CVE-2026-54183MEDIUMApache Airflow: Airflow Variables were not masked in the UI for authenticated usersEPSS 0.6%CVE-2026-48891MEDIUMApache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.targetEPSS 0.6%CVE-2026-75158MEDIUMApache Airflow: Assets events API returns asset events for every Dag with no per-Dag authorization filterEPSS 0.6%CVE-2024-54016MEDIUMcompression bomb attack in Apache Seata ServerEPSS 0.6%CVE-2026-68525CRITICALApache Tomcat: Redirect after FORM auth may bypass method specific constraintsEPSS 0.6%CVE-2026-58624MEDIUMApache MINA SSHD: Remote execution of JGit commands can write files on the serverEPSS 0.6%CVE-2026-24013CRITICALApache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPCEPSS 0.6%CVE-2026-39999HIGHApache APISIX: JWT Algorithm Confusion allows authentication bypassEPSS 0.6%CVE-2026-63016MEDIUMApache InLong: Ordinary users can create new packagesEPSS 0.6%