← All vendors

apache

451 known vulnerabilities affecting apache products.

Products

traffic_server 41 airflow 34 cxf 27 tomcat 26 thrift 23 cloudstack 20 http_server 15 camel 14 answer 12 ranger 11 wicket 11 inlong 10 activemq 10 fory 9 artemis 8 apache-airflow-providers-fab 8 syncope 8 activemq_broker 7 qpid_broker-j 7 qpid_proton-dotnet 6 qpid_proton-j 6 nifi 6 nimble 6 opennlp 6

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-23904 Medium 0.5% 7.3 Kyuubi Engine UI proxy accepts a host and port from the request path and proxies…
CVE-2026-58151 Medium 0.5% 7.5 Apache Traffic Server can be crashed or driven to resource exhaustion by abusive…
CVE-2026-65324 Medium 0.5% 7.5 Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or …
CVE-2026-62391 Medium 0.5% 8.1 The security fix for CVE-2025-66518 is incomplete. Any client who can access to …
CVE-2026-68979 Medium 0.5% 9.8 Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API me…
CVE-2026-50076 Medium 0.5% 9.1 Deserialization of Untrusted Data in the Java replace-resolve path in Apache For…
CVE-2026-49845 Medium 0.5% 9.8 SQL injection in Hive Metastore direct SQL partition-name resolution in Apache H…
CVE-2026-68981 Medium 0.5% 7.5 Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the appl…
CVE-2026-66143 Medium 0.5% 7.5 It is possible to bypass the maximum number of normalized policy alternatives th…
CVE-2026-63040 Medium 0.5% 8.1 Files or Directories Accessible to External Parties vulnerability in Apache InLo…
CVE-2026-63042 Medium 0.5% 8.1 Files or Directories Accessible to External Parties vulnerability in Apache InLo…
CVE-2026-56452 Medium 0.5% 7.5 Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD i…
CVE-2026-34501 Medium 0.5% 7.5 Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redi…
CVE-2026-34502 Medium 0.5% 7.5 Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memc…
CVE-2026-76186 Medium 0.5% 9.1 Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager tak…
CVE-2026-44631 Medium 0.5% 9.8 Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular express…
CVE-2026-47065 Medium 0.5% 9.8 ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via j…
CVE-2026-79993 Medium 0.5% 7.5 The `deleteContainer` opcode (0x14/20) is processed without verifying the caller…
CVE-2026-40682 Medium 0.5% 9.1 XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP D…
CVE-2026-66144 Medium 0.5% 7.5 Although remote policy references are not retrieved during policy normalization,…
CVE-2026-48834 Medium 0.5% 7.5 Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answ…
CVE-2026-67589 Medium 0.5% 7.5 A pre-authentication attacker could leverage type size/count handling to cause e…
CVE-2026-67590 Medium 0.5% 7.5 A pre-authentication attacker could leverage type nesting to cause a StackOverfl…
CVE-2026-66274 Medium 0.5% 7.5 A pre-authentication attacker could leverage type nesting to cause a StackOverfl…
CVE-2026-67465 Medium 0.5% 7.5 A pre-authentication attacker could leverage unbounded symbol value caching to c…
CVE-2026-67551 Medium 0.5% 7.5 pre-authentication attacker could leverage type size/count handling to cause exc…
CVE-2026-68074 Medium 0.5% 7.5 A pre-authentication attacker could leverage unbounded symbol value caching to c…
CVE-2026-49363 Medium 0.5% 7.5 An unauthenticated remote attacker connecting with the CORE protocol can discove…
CVE-2026-49298 Medium 0.5% 8.8 A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker po…
CVE-2026-59878 Medium 0.5% 7.5 Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ…
CVE-2026-58076 Medium 0.5% 8.8 Apache Airflow's serialization layer reconstructed exception nodes by calling `i…
CVE-2026-67588 Medium 0.5% 7.5 A pre-authentication attacker could leverage unbounded symbol value caching to c…
CVE-2026-67552 Medium 0.5% 7.5 A pre-authentication attacker could leverage type nesting to cause a StackOverfl…
CVE-2026-68060 Medium 0.5% 7.5 A pre-authentication attacker could leverage type size/count handling to cause e…
CVE-2026-68073 Medium 0.5% 7.5 A pre-authentication attacker could leverage type nesting to cause a StackOverfl…
CVE-2026-86462 Medium 0.5% 9.1 Apache Airflow FAB provider: changing a user's password through the Admin user-e…
CVE-2026-48913 Medium 0.5% 7.3 Use After Free vulnerability in Apache HTTP Server module mod_http2 when file ha…
CVE-2026-66142 Medium 0.5% 7.5 Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that…
CVE-2026-67592 Medium 0.5% 7.5 It was not possible to govern the maximum number of transfer frames per incoming…
CVE-2026-28811 Medium 0.5% 7.5 Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3.…
CVE-2026-41084 Medium 0.5% 7.5 A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{d…
CVE-2026-62418 Medium 0.5% 8.1 Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability i…
CVE-2026-56207 Medium 0.5% 9.8 Signature of Bearer token is not verified in last step of SAML2 authentication f…
CVE-2026-67211 Medium 0.5% 7.5 OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellMod…
CVE-2026-54225 Medium 0.5% 7.5 Apache CXF allows to control the maximum attachment size via the "attachment-max…
CVE-2026-57819 Medium 0.5% 7.5 Apache CXF allows to set a limit on the number of form parameters in a JAX-RS me…
CVE-2026-58153 Medium 0.5% 8.3 Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without …
CVE-2026-71300 Medium 0.5% 9.8 Improper input validation vulnerability in Apache Camel Atmosphere Websocket com…
CVE-2026-50112 Medium 0.5% 8.8 SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a…
CVE-2026-50645 Medium 0.5% 7.5 There is no restriction on the amount of attachment headers that a message can c…
← Prev Page 4 of 10 Next →