← All vendors

apache

451 known vulnerabilities affecting apache products.

Products

traffic_server 41 airflow 34 cxf 27 tomcat 26 thrift 23 cloudstack 20 http_server 15 camel 14 answer 12 ranger 11 wicket 11 inlong 10 activemq 10 fory 9 artemis 8 apache-airflow-providers-fab 8 syncope 8 activemq_broker 7 qpid_broker-j 7 qpid_proton-dotnet 6 qpid_proton-j 6 nifi 6 nimble 6 opennlp 6

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-57834 Medium 0.4% 10.0 Apache Traffic Server allows request smuggling if chunked messages are malformed…
CVE-2026-49364 Medium 0.4% 9.1 An unauthenticated network-adjacent attacker can leverage discovery to capture c…
CVE-2026-73334 Medium 0.4% 8.1 Potential problem for users of the org.apache.parquet.crypto.keytools package in…
CVE-2026-33267 Medium 0.4% 10.0 Improper Input Validation vulnerability in Apache Traffic Server. This issue af…
CVE-2026-48911 Medium 0.4% 7.5 Insufficient Verification of Data Authenticity vulnerability in Apache Answer. …
CVE-2026-58150 Medium 0.4% 10.0 Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allo…
CVE-2026-55814 Medium 0.4% 7.5 Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. User…
CVE-2026-58179 Medium 0.4% 8.1 The Apache Traffic Server regex_remap plugin overflows the stack and integers fr…
CVE-2026-32227 Medium 0.4% 9.8 SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects …
CVE-2026-63046 Medium 0.4% 8.8 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection…
CVE-2026-58189 Medium 0.4% 7.5 Apache Traffic Server allows redirect-limit bypass when plugins reset the retry …
CVE-2026-45813 Medium 0.4% 8.8 Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apa…
CVE-2026-34191 Medium 0.3% 9.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti…
CVE-2026-58184 Medium 0.3% 8.2 The Apache Traffic Server header_rewrite plugin can crash or corrupt memory duri…
CVE-2026-60053 Medium 0.3% 9.1 Insufficient Session Expiration vulnerability in Apache Answer. This issue affe…
CVE-2026-65948 Medium 0.3% 7.3 UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:…
CVE-2026-57818 Medium 0.3% 8.1 A race condition in JCacheCodeDataProvider allows an attacker to redeem a single…
CVE-2026-49050 Medium 0.3% 8.8 General user can mint admin access tokens via /access-tokens This issue affec…
CVE-2026-45811 Medium 0.3% 7.5 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerabi…
CVE-2026-50622 Medium 0.3% 8.8 Description: Missing Authorization in Apache Atlas. A missing authorization vuln…
CVE-2026-59655 Medium 0.3% 7.5 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac…
CVE-2026-59780 Medium 0.3% 7.5 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac…
CVE-2026-61397 Medium 0.3% 7.5 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac…
CVE-2026-65942 Medium 0.3% 7.5 TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.…
CVE-2026-66722 Medium 0.3% 7.2 Improper authorization for CRUD operations on Project Roles and Project Role per…
CVE-2026-58177 Medium 0.3% 8.1 The Apache Traffic Server Cripts framework has out-of-bounds writes, path traver…
CVE-2026-59654 Medium 0.3% 7.5 Missing Release of Resource after Effective Lifetime vulnerability in Apache Clo…
CVE-2026-24033 Medium 0.3% 7.2 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')…
CVE-2026-59085 Medium 0.3% 9.1 Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook …
CVE-2026-59799 Medium 0.3% 8.8 Improper Privilege Management vulnerability in Apache CloudStack's Two-factor au…
CVE-2026-68980 Medium 0.3% 9.1 Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets …
CVE-2026-58159 Medium 0.3% 8.2 Apache Traffic Server can bypass IP access controls on UDS listeners and through…
CVE-2026-61398 Medium 0.3% 9.1 Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI …
CVE-2026-41920 Medium 0.3% 9.3 Improper Access Control vulnerability in Apache Traffic Server. This issue affe…
CVE-2026-50222 Medium 0.3% 7.5 Missing Authorization, Exposure of Sensitive Information to an Unauthorized Acto…
CVE-2026-62440 Medium 0.3% 9.1 Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service …
CVE-2026-56624 Medium 0.3% 7.3 Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA S…
CVE-2026-50631 Medium 0.3% 7.4 A race condition in AbstractOAuthDataProvider allows concurrent requests using t…
CVE-2026-48145 Medium 0.3% 7.5 Improper Validation of Certificate with Host Mismatch vulnerability in Apache Th…
CVE-2026-58157 Medium 0.3% 8.7 Apache Traffic Server can reuse server sessions and tunnels improperly, exposing…
CVE-2026-80354 Medium 0.3% 8.1 Authorization bypass through User-Controlled key vulnerability in Apache Camel K…
CVE-2026-53561 Medium 0.3% 7.4 An improper authentication vulnerability in HiveServer2 SAML bearer-token valida…
CVE-2026-63687 Medium 0.3% 9.1 Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT in…
CVE-2026-65583 Medium 0.3% 9.1 Apache CXF’s OIDC relying-party token validation could accept self-issued ID tok…
CVE-2026-59969 Medium 0.3% 7.5 Apache ZooKeeper quorum TLS fails to enforce peer hostname verification in FIPS-…
CVE-2026-48144 Medium 0.3% 9.1 Improper Validation of Certificate with Host Mismatch vulnerability in Apache Th…
CVE-2026-71290 Medium 0.2% 9.1 Improper TLS hostname verification vulnerability in Apache HttpComponents Client…
CVE-2026-86466 Medium 0.2% 8.1 Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager do…
CVE-2026-58162 Medium 0.2% 10.0 The Apache Traffic Server certifier plugin generates certificates based on attac…
CVE-2026-59657 Medium 0.2% 7.5 Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack wi…
← Prev Page 6 of 10 Next →