Vulnerabilidades em Apache Software Foundation

2.397 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-24281MEDIUMApache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManagerEPSS 0.6%CVE-2025-48208HIGHApache HertzBeat (incubating): Jmx JNDI injection vulnerabilityEPSS 0.6%CVE-2024-48944MEDIUMApache Kylin: SSRF vulnerability in the diagnosis apiEPSS 0.6%CVE-2024-29733LOWApache Airflow FTP Provider: FTP_TLS instance with unverified SSL contextEPSS 0.6%CVE-2026-31380MEDIUMApache OFBiz: FreeMarker SSTI via Duplicate Parameter Sanitization BypassEPSS 0.6%CVE-2026-49434HIGHApache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: LdapNetworkConnector instantiates denied transports and a remote-properties brokerEPSS 0.6%CVE-2026-29207MEDIUMApache OFBiz: Low-Privilege SSTI Leading to RCE in the Content ComponentEPSS 0.6%CVE-2026-66755MEDIUMApache Tika: Arbitrary Local File Read in ISArchiveParserEPSS 0.6%CVE-2026-35086MEDIUMApache OFBiz: Authenticated Remote Code Execution via Unsafe Template Expansion in email servicesEPSS 0.6%CVE-2026-29145CRITICALApache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabledEPSS 0.6%CVE-2026-46585HIGHApache Camel Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search queryEPSS 0.6%CVE-2026-24735HIGHApache Answer: Revision API Improper Access Control leads to Information DisclosureEPSS 0.6%CVE-2025-27427LOWApache ActiveMQ Artemis: Address routing-type can be updated by user without the createAddress permissionEPSS 0.6%CVE-2026-58189HIGHApache Traffic Server: Plugins resetting the redirect counter enable SSRF amplificationEPSS 0.6%CVE-2026-49157HIGHApache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by defaultEPSS 0.6%CVE-2024-45537MEDIUMApache Druid: Users can provide MySQL JDBC properties not on allow listEPSS 0.6%CVE-2026-55994HIGHApache Camel Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling control over internal behaviourEPSS 0.6%CVE-2024-25141CRITICALApache Airflow Mongo Provider: Certificate validation isn't respected even if SSL is enabled for apache-airflow-providers-mongoEPSS 0.6%CVE-2026-46592HIGHApache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operationEPSS 0.6%CVE-2025-53606CRITICALApache Seata (incubating): Deserialization of untrusted Data in Apache Seata ServerEPSS 0.6%