← All vendors

apache

451 known vulnerabilities affecting apache products.

Products

traffic_server 41 airflow 34 cxf 27 tomcat 26 thrift 23 cloudstack 20 http_server 15 camel 14 answer 12 ranger 11 wicket 11 inlong 10 activemq 10 fory 9 artemis 8 apache-airflow-providers-fab 8 syncope 8 activemq_broker 7 qpid_broker-j 7 qpid_proton-dotnet 6 qpid_proton-j 6 nifi 6 nimble 6 opennlp 6

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-32327 Medium 0.5% 9.1 A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack ag…
CVE-2026-61899 Medium 0.5% 7.5 Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows…
CVE-2026-65183 Medium 0.5% 8.1 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat…
CVE-2026-73635 Medium 0.5% 7.5 Allocation of resources without limits or throttling vulnerability in Apache Str…
CVE-2026-57817 Medium 0.4% 8.1 The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the…
CVE-2026-50627 Medium 0.4% 9.1 The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Aud…
CVE-2026-59243 Medium 0.4% 9.8 The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` w…
CVE-2026-66756 Medium 0.4% 9.8 Improper Protection of Alternate Path vulnerability in Apache Tika. This issue …
CVE-2026-80352 Medium 0.4% 9.8 Improper Control of Generation of Code ('Code Injection') vulnerability in Apach…
CVE-2026-66755 Medium 0.4% 7.5 Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apac…
CVE-2026-49486 Medium 0.4% 7.5 The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_T…
CVE-2026-58161 Medium 0.4% 7.5 Apache Traffic Server can crash from null dereferences and dangling references i…
CVE-2026-82617 Medium 0.4% 9.8 The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNam…
CVE-2026-49157 Medium 0.4% 8.8 Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affe…
CVE-2026-35554 Medium 0.4% 8.7 A race condition in the Apache Kafka Java producer client’s buffer pool manageme…
CVE-2026-59739 Medium 0.4% 7.5 Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due t…
CVE-2026-71559 Medium 0.4% 7.5 Deserialization of Untrusted Data vulnerability in the Go implementation of Apac…
CVE-2026-58188 Medium 0.4% 8.2 Several Apache Traffic Server experimental plugins have memory-safety and limit-…
CVE-2025-65114 Medium 0.4% 7.5 Apache Traffic Server allows request smuggling if chunked messages are malformed…
CVE-2026-78329 Medium 0.4% 9.8 Improper input validation vulnerability in Apache Camel Undertow component. T…
CVE-2026-66257 Medium 0.4% 7.5 A pre-authentication attacker could leverage unbounded symbol value caching to c…
CVE-2026-66273 Medium 0.4% 7.5 A pre-authentication attacker could leverage type size/count handling to cause e…
CVE-2026-68481 Medium 0.4% 7.5 In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still …
CVE-2026-73634 Medium 0.4% 7.5 Uncontrolled resource consumption vulnerability in Apache Struts. An application…
CVE-2026-58182 Medium 0.4% 8.6 The Apache Traffic Server ts_lua plugin mishandles initialization, transform con…
CVE-2026-61466 Medium 0.4% 9.1 In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization s…
CVE-2026-71560 Medium 0.4% 9.1 Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue…
CVE-2026-58186 Medium 0.4% 7.5 The Apache Traffic Server webp_transform plugin can decode unsafely and serve mi…
CVE-2026-68968 Medium 0.4% 7.5 Apache Airflow's Backfill API authorized a request against a Dag id supplied by …
CVE-2026-22068 Medium 0.4% 8.2 Regular Expression without Anchors vulnerability in Apache Traffic Server. This…
CVE-2026-28814 Medium 0.4% 7.5 Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki …
CVE-2026-65432 Medium 0.4% 7.5 Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which dis…
CVE-2026-66908 Medium 0.4% 7.5 Improper Authentication vulnerability in Apache Camel Platform HTTP Main compone…
CVE-2026-47342 Medium 0.4% 8.8 A privilege escalation vulnerability in Apache OFBiz allows a low-privileged aut…
CVE-2026-64958 Medium 0.4% 7.5 An incomplete fix for CVE-2026-50645 means that it is still possible to perform …
CVE-2026-58155 Medium 0.4% 9.3 Apache Traffic Server truncates over-long header names, allowing header aliasing…
CVE-2026-28812 Medium 0.4% 9.8 UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 w…
CVE-2026-58175 Medium 0.4% 7.5 Apache Traffic Server leaks memory when handling HostDB SRV records. This issue…
CVE-2026-58178 Medium 0.4% 7.5 The Apache Traffic Server ESI plugin can recurse without bound and fetch attacke…
CVE-2026-58180 Medium 0.4% 7.5 The Apache Traffic Server txn_box plugin overflows the stack from attacker-contr…
CVE-2026-58154 Medium 0.4% 8.9 Apache Traffic Server can write out of bounds or overflow integers while parsing…
CVE-2026-68079 Medium 0.4% 9.8 In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code…
CVE-2026-60023 Medium 0.4% 7.5 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac…
CVE-2026-58164 Medium 0.4% 7.5 Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in…
CVE-2026-58181 Medium 0.4% 7.5 The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack …
CVE-2026-40920 Medium 0.4% 9.8 Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= …
CVE-2026-74761 Medium 0.4% 7.5 Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Bro…
CVE-2026-42252 Medium 0.4% 9.1 Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passin…
CVE-2026-58163 Medium 0.4% 7.5 Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corr…
CVE-2025-49506 Medium 0.4% 7.5 APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not c…
← Prev Page 5 of 10 Next →