apache
451 known vulnerabilities affecting apache products.
Products
traffic_server 41
airflow 34
cxf 27
tomcat 26
thrift 23
cloudstack 20
http_server 15
camel 14
answer 12
ranger 11
wicket 11
inlong 10
activemq 10
fory 9
artemis 8
apache-airflow-providers-fab 8
syncope 8
activemq_broker 7
qpid_broker-j 7
qpid_proton-dotnet 6
qpid_proton-j 6
nifi 6
nimble 6
opennlp 6
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-28813 | Medium | 0.2% | 8.8 | Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to cs… | |
| CVE-2026-75156 | Medium | 0.2% | 9.1 | Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the iss… | |
| CVE-2026-35563 | Medium | 0.2% | 8.5 | It was identified that the LDAP client implementation in version 2.1.7 does not … | |
| CVE-2026-27173 | Medium | 0.2% | 8.7 | JWT tokens that were used by workers in Kubernetes Executors have been exposed t… | |
| CVE-2026-68745 | Medium | 0.1% | 8.1 | Certificate validation failures in SAML authentication in Apache CloudStack 4.20… | |
| CVE-2019-17569 | Low | 8.9% | 4.8 | The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and … | |
| CVE-2021-36374 | Low | 2.6% | 5.5 | When reading a specially crafted ZIP archive, or a derived formats, an Apache An… | |
| CVE-2021-36373 | Low | 2.5% | 5.5 | When reading a specially crafted TAR archive an Apache Ant build can be made to … | |
| CVE-2026-42253 | Low | 1.1% | 6.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti… | |
| CVE-2026-41606 | Low | 1.1% | 5.3 | Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apach… | |
| CVE-2020-17521 | Low | 1.1% | 5.5 | Apache Groovy provides extension methods to aid with creating temporary director… | |
| CVE-2026-70449 | Low | 0.9% | 5.3 | Improper validation of resource URL attributes in Apache Wicket allows an unauth… | |
| CVE-2026-41607 | Low | 0.9% | 6.5 | Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Th… | |
| CVE-2026-23907 | Low | 0.9% | 5.3 | This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.… | |
| CVE-2026-45249 | Low | 0.7% | 6.1 | A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines… | |
| CVE-2026-43868 | Low | 0.7% | 5.3 | Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. Thi… | |
| CVE-2026-40861 | Low | 0.7% | 6.5 | A Dag author could either (a) create a symlink under their task's log directory … | |
| CVE-2026-32773 | Low | 0.7% | 6.1 | There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which… | |
| CVE-2026-48828 | Low | 0.7% | 6.5 | The Bulk Variables API in Apache Airflow called the redactor without passing the… | |
| CVE-2026-48892 | Low | 0.7% | 6.5 | The Config API in Apache Airflow surfaced per-key secrets-backend overrides (env… | |
| CVE-2026-49487 | Low | 0.7% | 6.5 | In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpo… | |
| CVE-2026-48891 | Low | 0.6% | 4.3 | A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied t… | |
| CVE-2026-58624 | Low | 0.6% | 5.4 | Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a… | |
| CVE-2026-49818 | Low | 0.6% | 6.5 | The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names… | |
| CVE-2026-59242 | Low | 0.6% | 5.4 | Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` end… | |
| CVE-2026-54048 | Low | 0.6% | 5.3 | Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' … | |
| CVE-2026-44615 | Low | 0.6% | 6.5 | Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is … | |
| CVE-2026-46745 | Low | 0.6% | 5.3 | Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability … | |
| CVE-2026-76986 | Low | 0.6% | 6.1 | Improper neutralization of input during web page generation in Apache Wicket. o… | |
| CVE-2026-63317 | Low | 0.6% | 5.6 | Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Na… | |
| CVE-2026-46452 | Low | 0.6% | 5.3 | Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reass… | |
| CVE-2026-43951 | Low | 0.5% | 6.5 | Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_… | |
| CVE-2026-73180 | Low | 0.5% | 6.8 | Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the… | |
| CVE-2026-66299 | Low | 0.5% | 5.3 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket cha… | |
| CVE-2026-29170 | Low | 0.5% | 6.1 | A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory li… | |
| CVE-2026-44617 | Low | 0.5% | 6.5 | LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 … | |
| CVE-2026-49328 | Low | 0.5% | 5.3 | Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache … | |
| CVE-2026-75802 | Low | 0.5% | 5.4 | AjaxEditableChoiceLabel in wicket-extensions, when constructed with a non-null I… | |
| CVE-2026-76982 | Low | 0.5% | 5.4 | Improper neutralization of input during web page generation in Apache Wicket. o… | |
| CVE-2026-76983 | Low | 0.5% | 5.4 | Improper neutralization of input during web page generation in Apache Wicket. T… | |
| CVE-2026-76984 | Low | 0.5% | 5.4 | Improper neutralization of input during web page generation in Apache Wicket. o… | |
| CVE-2026-76985 | Low | 0.5% | 5.4 | Improper neutralization of input during web page generation in Apache Wicket. o… | |
| CVE-2026-57822 | Low | 0.5% | 6.5 | When the broker is processing message-based management requests, sent by an auth… | |
| CVE-2026-40564 | Low | 0.5% | 6.5 | Files or Directories Accessible to External Parties, Server-Side Request Forgery… | |
| CVE-2026-64607 | Low | 0.5% | 5.3 | HttpClient based on the classic i/o model fails to correctly release the underly… | |
| CVE-2026-33582 | Low | 0.5% | 6.5 | Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. … | |
| CVE-2026-55970 | Low | 0.5% | 6.5 | Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affect… | |
| CVE-2026-68868 | Low | 0.5% | 6.5 | The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provi… | |
| CVE-2026-40963 | Low | 0.5% | 3.1 | The structure_data endpoint in the Airflow UI returned external dependency graph… | |
| CVE-2026-62764 | Low | 0.5% | 6.5 | Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. A… |