Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-49296MEDIUMApache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagSources/{dag_id}EPSS 0.6%CVE-2026-34500MEDIUMApache Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabledEPSS 0.6%CVE-2026-48203CRITICALApache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fieldsEPSS 0.6%CVE-2026-40563HIGHApache Atlas: Script injection allows access to unintended dataEPSS 0.6%CVE-2026-48205CRITICALApache Camel DNS: The dns.* and term Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to influence internal behaviourEPSS 0.6%CVE-2026-59245HIGHApache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the global all-DAGs permission (access_control privilege escalation via resource_name() collision)EPSS 0.6%CVE-2026-31387MEDIUMApache OFBiz: Cookie Manipulation Allows Authenticated JWT Forgery and Account ImpersonationEPSS 0.6%CVE-2026-86460CRITICALApache Syncope: Cypher Injection via FIQL Search on Neo4j PersistenceEPSS 0.6%CVE-2025-48392HIGHApache IoTDB: DoS VulnerabilityEPSS 0.6%CVE-2026-40008CRITICALApache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPCEPSS 0.6%CVE-2026-41041CRITICALApache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended API endpoints.EPSS 0.6%CVE-2026-31908CRITICALApache APISIX: forward auth plugin allows header injectionEPSS 0.6%CVE-2026-55276CRITICALApache Tomcat: Logged effective web.xml is incompleteEPSS 0.6%CVE-2025-66249MEDIUMApache Livy: Unauthorized directory accessEPSS 0.6%CVE-2026-53434CRITICALApache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM ConnectorEPSS 0.6%CVE-2026-68871MEDIUMApache Airflow Yandex provider: yandex Lockbox backend: team-scope guard bypass resolves another team's Connection or VariableEPSS 0.6%CVE-2026-68868MEDIUMApache Airflow Google provider: google Secret Manager backend: team scope is never applied, exposing every team's Connections and VariablesEPSS 0.6%CVE-2017-12618—Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functioEPSS 0.6%CVE-2026-48726MEDIUMApache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logout pathEPSS 0.6%CVE-2026-68569HIGHApache Tomcat: Principal lookup can fail open in some casesEPSS 0.6%