Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2026-68971MEDIUMApache Airflow: Cross-team authorization bypass in the asset materialization and dag-run result endpointsEPSS 0.6%CVE-2026-65942HIGHApache Ranger: Clients accept TLS certificates issued for other hostnamesEPSS 0.6%CVE-2026-63621MEDIUMApache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategyEPSS 0.6%CVE-2026-34191CRITICALApache Portable Runtime Utility: SQL Injection in apr_dbd_oracleEPSS 0.6%CVE-2026-58177HIGHApache Traffic Server: Memory-safety and path-traversal errors in the Cripts frameworkEPSS 0.6%CVE-2023-41180—Apache NiFi MiNiFi C++: Incorrect Certificate Validation in InvokeHTTP for MiNiFi C++EPSS 0.6%CVE-2026-59085CRITICALApache CloudStack: Server-Side Request Forgery (SSRF) vulnerability in webhook moduleEPSS 0.6%CVE-2026-58158HIGHApache Traffic Server: PROXY protocol parsing has port truncation and a stack overflowEPSS 0.6%CVE-2026-58152MEDIUMApache Traffic Server: Integer-handling errors in HPACK/XPACK decoding corrupt memoryEPSS 0.6%CVE-2026-40006HIGHApache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiverEPSS 0.6%CVE-2026-33930HIGHApache Traffic Server: Buffer overflow via Host field that has a long string valueEPSS 0.6%CVE-2026-58187MEDIUMApache Traffic Server: Multiplexer plugin chunk decoder enables a denial of serviceEPSS 0.6%CVE-2026-24015CRITICALApache IoTDB: Insecure Default Configuration VulnerabilityEPSS 0.6%CVE-2026-31910HIGHApache OFBiz: Improper Input Validation in UI Factory Classes Leads to SSRF and Blind File AccessEPSS 0.6%CVE-2024-45772MEDIUMApache Lucene Replicator: Security Vulnerability in Lucene Replicator - Deserialization IssueEPSS 0.6%CVE-2026-76646HIGHApache MyFaces: Denial of Service via Unbounded Request ParsingEPSS 0.6%CVE-2026-65100MEDIUMApache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header encodeEPSS 0.6%CVE-2025-54550HIGHApache Airflow: RCE by race condition in example_xcom dagEPSS 0.6%CVE-2024-39928HIGHApache Linkis Spark EngineConn: Commons Lang's RandomStringUtils Random string security vulnerabilityEPSS 0.6%CVE-2026-42404MEDIUMApache Neethi: Unrestricted HTTP Redirect Following in Policy ReferencesEPSS 0.6%