Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-68872MEDIUMApache Airflow Amazon provider: amazon SSM / Secrets Manager backends: team-scope guard bypass resolves another team's Connection or VariableEPSS 0.6%CVE-2026-58179CRITICALApache Traffic Server: regex_remap plugin overflows the stack from attacker inputEPSS 0.6%CVE-2026-59655HIGHApache CloudStack: Unauthenticated OAuth provider client-secret disclosureEPSS 0.6%CVE-2026-61397HIGHApache CloudStack: OAuth2 Token Cross-Request LeakEPSS 0.6%CVE-2026-59780HIGHApache CloudStack: LDAP provider configuration disclosureEPSS 0.6%CVE-2026-74848HIGHApache APISIX: Cross-user response poisoning in serverless pluginsEPSS 0.6%CVE-2025-66675HIGHApache Struts: File leak in multipart request processing causes disk exhaustion (DoS) - version ranges fixedEPSS 0.6%CVE-2026-23552CRITICALApache Camel: Camel-Keycloak: Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicyEPSS 0.6%CVE-2024-48988HIGHApache StreamPark: SQL injection vulnerabilityEPSS 0.6%CVE-2025-47713HIGHApache CloudStack: Domain Admin can reset Admin password in Root DomainEPSS 0.6%CVE-2026-42252CRITICALApache Airflow: BashOperator Jinja2 injection via dag_run.conf — low-privilege user patternEPSS 0.6%CVE-2025-47849HIGHApache CloudStack: Insecure access of user's API/Secret Keys in the same domainEPSS 0.6%CVE-2026-35565MEDIUMApache Storm UI: Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Storm UIEPSS 0.6%CVE-2026-59654MEDIUMApache CloudStack: DoS caused by database connections leakEPSS 0.6%CVE-2026-42812CRITICALApache Polaris: No protection on `write.metadata.path`EPSS 0.6%CVE-2026-58184HIGHApache Traffic Server: header_rewrite plugin cookie handling can corrupt memoryEPSS 0.6%CVE-2026-41919CRITICALApache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN ConstructionEPSS 0.6%CVE-2026-44630HIGHApache IoTDB: RPC service denial of service via unchecked Thrift string lengthEPSS 0.6%CVE-2026-30778HIGHApache SkyWalking: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.EPSS 0.6%CVE-2025-54656MEDIUMApache Struts Extras: Improper Output Neutralization for LogsEPSS 0.6%