apache
451 known vulnerabilities affecting apache products.
Products
traffic_server 41
airflow 34
cxf 27
tomcat 26
thrift 23
cloudstack 20
http_server 15
camel 14
answer 12
ranger 11
wicket 11
inlong 10
activemq 10
fory 9
artemis 8
apache-airflow-providers-fab 8
syncope 8
activemq_broker 7
qpid_broker-j 7
qpid_proton-dotnet 6
qpid_proton-j 6
nifi 6
nimble 6
opennlp 6
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-61483 | Medium | 0.8% | 7.5 | ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache L… | |
| CVE-2026-64608 | Medium | 0.8% | 9.8 | Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implemen… | |
| CVE-2026-75005 | Medium | 0.8% | 7.5 | Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single sm… | |
| CVE-2026-65927 | Medium | 0.8% | 7.5 | Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the re… | |
| CVE-2026-71257 | Medium | 0.8% | 7.5 | Apache Wicket enforces the upload limits configured on a form or upload field wh… | |
| CVE-2026-67260 | Medium | 0.8% | 7.3 | Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `… | |
| CVE-2026-64609 | Medium | 0.8% | 9.1 | Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-cop… | |
| CVE-2026-41871 | Medium | 0.8% | 9.8 | Missing Authorization, Use of Externally-Controlled Input to Select Classes or C… | |
| CVE-2026-41869 | Medium | 0.8% | 9.1 | Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerabi… | |
| CVE-2026-65905 | Medium | 0.8% | 9.8 | Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST … | |
| CVE-2026-65637 | Medium | 0.8% | 9.8 | Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix f… | |
| CVE-2026-86792 | Medium | 0.8% | 8.8 | Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted… | |
| CVE-2026-63071 | Medium | 0.8% | 9.8 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An … | |
| CVE-2026-53405 | Medium | 0.7% | 9.8 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An … | |
| CVE-2026-44185 | Medium | 0.7% | 7.3 | Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests … | |
| CVE-2026-42588 | Medium | 0.7% | 8.1 | Improper Input Validation, Improper Control of Generation of Code ('Code Injecti… | |
| CVE-2026-58065 | Medium | 0.7% | 8.1 | The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHos… | |
| CVE-2026-69223 | Medium | 0.7% | 9.1 | Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). … | |
| CVE-2026-47430 | Medium | 0.7% | 7.5 | ## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `… | |
| CVE-2026-63043 | Medium | 0.7% | 7.5 | Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from… | |
| CVE-2026-64606 | Medium | 0.7% | 9.8 | Deserialization of untrusted data vulnerability that may allow class-registratio… | |
| CVE-2026-34356 | Medium | 0.7% | 7.5 | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious ba… | |
| CVE-2026-42027 | Medium | 0.7% | 9.8 | Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoad… | |
| CVE-2026-82310 | Medium | 0.7% | 7.2 | Apache Airflow FAB provider: deactivating a user account does not stop tokens is… | |
| CVE-2026-59173 | Medium | 0.7% | 7.5 | Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This … | |
| CVE-2026-66256 | Medium | 0.7% | 7.2 | ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability … | |
| CVE-2026-41870 | Medium | 0.7% | 8.8 | Missing Authorization, Improper Control of Generation of Code ('Code Injection')… | |
| CVE-2026-44930 | Medium | 0.7% | 9.8 | An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS s… | |
| CVE-2026-57967 | Medium | 0.7% | 9.8 | An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH pa… | |
| CVE-2026-62183 | Medium | 0.7% | 9.8 | Improper Privilege Management vulnerability in Apache Syncope. When: * the all… | |
| CVE-2026-29167 | Medium | 0.7% | 9.8 | Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-director… | |
| CVE-2026-42537 | Medium | 0.7% | 9.8 | Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are… | |
| CVE-2026-60080 | Medium | 0.7% | 7.3 | Use After Free vulnerability in the Rust deserialization logic of Apache Fory. T… | |
| CVE-2026-50628 | Medium | 0.7% | 9.8 | A logic error in OAuthRequestFilter rejects legitimate requests originating from… | |
| CVE-2026-34884 | Medium | 0.7% | 9.8 | SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability … | |
| CVE-2026-53421 | Medium | 0.7% | 9.8 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. A… | |
| CVE-2026-63041 | Medium | 0.7% | 8.8 | Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APIS… | |
| CVE-2026-45360 | Medium | 0.7% | 7.3 | Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomRef… | |
| CVE-2025-58136 | Medium | 0.7% | 7.5 | A bug in POST request handling causes a crash under a certain condition. This i… | |
| CVE-2026-66909 | Medium | 0.7% | 9.8 | Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessag… | |
| CVE-2026-44416 | Medium | 0.7% | 9.8 | Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registr… | |
| CVE-2026-50223 | Medium | 0.7% | 8.8 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apach… | |
| CVE-2026-42782 | Medium | 0.7% | 7.2 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An … | |
| CVE-2026-40961 | Medium | 0.6% | 7.2 | A bug in the login redirect route in Apache Airflow allowed authenticated users … | |
| CVE-2026-55799 | Medium | 0.6% | 9.8 | Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger… | |
| CVE-2026-50632 | Medium | 0.6% | 8.1 | A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS c… | |
| CVE-2026-55969 | Medium | 0.6% | 7.5 | Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, n… | |
| CVE-2026-49158 | Medium | 0.6% | 7.5 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability i… | |
| CVE-2026-44417 | Medium | 0.6% | 7.5 | The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to … | |
| CVE-2026-58023 | Medium | 0.6% | 9.1 | Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue a… |