apache
451 known vulnerabilities affecting apache products.
Products
traffic_server 41
airflow 34
cxf 27
tomcat 26
thrift 23
cloudstack 20
http_server 15
camel 14
answer 12
ranger 11
wicket 11
inlong 10
activemq 10
fory 9
artemis 8
apache-airflow-providers-fab 8
syncope 8
activemq_broker 7
qpid_broker-j 7
qpid_proton-dotnet 6
qpid_proton-j 6
nifi 6
nimble 6
opennlp 6
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-58662 | Medium | 0.6% | 9.1 | Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerabi… | |
| CVE-2026-61486 | Medium | 0.6% | 9.8 | ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apa… | |
| CVE-2026-43869 | Medium | 0.6% | 7.3 | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Th… | |
| CVE-2026-48586 | Medium | 0.6% | 7.5 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability i… | |
| CVE-2026-68525 | Medium | 0.6% | 9.1 | Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication pro… | |
| CVE-2026-74848 | Medium | 0.6% | 7.5 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')… | |
| CVE-2026-61484 | Medium | 0.6% | 9.8 | ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability … | |
| CVE-2026-45816 | Medium | 0.6% | 7.5 | NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Requ… | |
| CVE-2026-67587 | Medium | 0.6% | 8.8 | Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re… | |
| CVE-2026-43871 | Medium | 0.6% | 7.5 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache T… | |
| CVE-2026-55968 | Medium | 0.6% | 7.5 | Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Th… | |
| CVE-2026-58389 | Medium | 0.6% | 7.5 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thr… | |
| CVE-2026-76187 | Medium | 0.6% | 9.8 | Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a c… | |
| CVE-2026-82311 | Medium | 0.6% | 9.8 | Apache Airflow FAB provider: resetting a user's password does not delete that us… | |
| CVE-2026-42440 | Medium | 0.6% | 7.5 | OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractM… | |
| CVE-2026-45815 | Medium | 0.6% | 7.5 | Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read… | |
| CVE-2026-57866 | Medium | 0.6% | 8.8 | Server side request forgery in Apache Impala versions 4.4.x and 4.5.x. Authenti… | |
| CVE-2026-73633 | Medium | 0.6% | 7.5 | Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Str… | |
| CVE-2026-45505 | Medium | 0.6% | 8.8 | Improper Input Validation, Improper Control of Generation of Code ('Code Injecti… | |
| CVE-2026-59245 | Medium | 0.6% | 8.1 | In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided … | |
| CVE-2026-49362 | Medium | 0.6% | 7.5 | An unauthenticated remote attacker can create arbitrary durable queues via the C… | |
| CVE-2026-45361 | Medium | 0.6% | 8.1 | Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key v… | |
| CVE-2026-65182 | Medium | 0.6% | 9.1 | Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat … | |
| CVE-2026-55976 | Medium | 0.6% | 9.1 | Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hiv… | |
| CVE-2026-41608 | Medium | 0.6% | 7.5 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability i… | |
| CVE-2026-63039 | Medium | 0.6% | 9.8 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti… | |
| CVE-2026-44186 | Medium | 0.6% | 7.3 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_… | |
| CVE-2026-49361 | Medium | 0.6% | 7.5 | Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDe… | |
| CVE-2026-66907 | Medium | 0.6% | 7.5 | Relative path traversal vulnerability in Apache Camel Google Storage component. … | |
| CVE-2026-48207 | Medium | 0.6% | 9.8 | Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializ… | |
| CVE-2026-66422 | Medium | 0.6% | 8.1 | Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref… | |
| CVE-2026-42359 | Medium | 0.6% | 8.8 | A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` … | |
| CVE-2026-56623 | Medium | 0.6% | 7.1 | Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SS… | |
| CVE-2026-61372 | Medium | 0.6% | 7.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v… | |
| CVE-2026-63038 | Medium | 0.6% | 9.8 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti… | |
| CVE-2026-65181 | Medium | 0.6% | 8.1 | Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a clie… | |
| CVE-2026-40542 | Medium | 0.6% | 7.3 | Missing critical step in authentication in Apache HttpClient 5.6 allows an attac… | |
| CVE-2026-67593 | Medium | 0.6% | 9.1 | A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause … | |
| CVE-2026-55971 | Medium | 0.6% | 9.8 | Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This is… | |
| CVE-2026-75020 | Medium | 0.5% | 8.1 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injecti… | |
| CVE-2026-73240 | Medium | 0.5% | 9.8 | Specifically crafted inputs may lead to git argument injection in Apache Allura.… | |
| CVE-2026-78254 | Medium | 0.5% | 7.4 | The ftp and scp tasks of Apache Ant can download files from a remote server. A m… | |
| CVE-2026-80351 | Medium | 0.5% | 9.8 | Improper neutralization of directives in dynamically evaluated code ('eval injec… | |
| CVE-2026-42535 | Medium | 0.5% | 9.1 | A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV… | |
| CVE-2026-66906 | Medium | 0.5% | 9.1 | Relative path traversal vulnerability in Apache Camel Azure Storage Blob compone… | |
| CVE-2026-63037 | Medium | 0.5% | 9.8 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti… | |
| CVE-2026-48827 | Medium | 0.5% | 7.1 | Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path v… | |
| CVE-2026-71558 | Medium | 0.5% | 9.8 | Heap type confusion vulnerability in Apache Fory C++ deserialization. This issu… | |
| CVE-2026-49875 | Medium | 0.5% | 9.8 | Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct … | |
| CVE-2026-68569 | Medium | 0.5% | 8.1 | Improper Authentication vulnerability in Apache Tomcat meant that in some circum… |