Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2025-33042HIGHApache Avro Java SDK: Code injection on Java generated codeEPSS 0.6%CVE-2026-29226HIGHApache OFBiz: Low-Privilege SSRF in Content ComponentEPSS 0.6%CVE-2025-59390CRITICALApache Druid: Kerberos authenticaton chooses a cryptographically unsecure secret if not configured explicitly.EPSS 0.6%CVE-2024-45720HIGHApache Subversion: Command line argument injection on Windows platformsEPSS 0.6%CVE-2026-66908HIGHApache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was acceptedEPSS 0.6%CVE-2024-48962HIGHApache OFBiz: Bypass SameSite restrictions with target redirection using URL parameters (SSTI and CSRF leading to RCE)EPSS 0.6%CVE-2026-57834HIGHApache Traffic Server: Malformed chunked message body allows request smugglingEPSS 0.6%CVE-2026-49098MEDIUMApache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter, allowing an HTTP client to redirect Kafka messages to an arbitrary topicEPSS 0.6%CVE-2026-40046HIGHApache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT: Missing fix for CVE-2025-66168: MQTT control packet remaining length field is not properly validatedEPSS 0.6%CVE-2024-41169HIGHApache Zeppelin: raft directory listing and file readEPSS 0.6%CVE-2024-53678MEDIUMApache VCL: SQL injection vulnerability in New Block Allocation formEPSS 0.6%CVE-2026-22068MEDIUMApache Traffic Server: Regex mappings match with malicious domain namesEPSS 0.6%CVE-2023-41267—Apache HDFS Provider error message suggested installation of incorrect pip packageEPSS 0.6%CVE-2018-11760—When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the SparkEPSS 0.6%CVE-2026-59799HIGHApache CloudStack: Missing Privilege Check in Two-Factor Authentication Disable FlowEPSS 0.6%CVE-2026-79993HIGHApache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znodeEPSS 0.6%CVE-2026-33267HIGHApache Traffic Server: Untrusted @ headers can spoof ATS internal metadataEPSS 0.6%CVE-2026-82232CRITICALApache Syncope: SQL injection via sort parameter in Task searchEPSS 0.6%CVE-2026-77051CRITICALApache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events searchEPSS 0.6%CVE-2023-42503—Apache Commons Compress: Denial of service via CPU consumption for malformed TAR fileEPSS 0.6%