apache
451 known vulnerabilities affecting apache products.
Products
traffic_server 41
airflow 34
cxf 27
tomcat 26
thrift 23
cloudstack 20
http_server 15
camel 14
answer 12
ranger 11
wicket 11
inlong 10
activemq 10
fory 9
artemis 8
apache-airflow-providers-fab 8
syncope 8
activemq_broker 7
qpid_broker-j 7
qpid_proton-dotnet 6
qpid_proton-j 6
nifi 6
nimble 6
opennlp 6
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-54183 | Low | 0.5% | 4.3 | Apache Airflow's secrets masker hides values stored under sensitive key names wh… | |
| CVE-2026-44616 | Low | 0.4% | 6.5 | LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm const… | |
| CVE-2026-63044 | Low | 0.4% | 5.4 | Server-Side Request Forgery (SSRF) vulnerability in Apache InLong. Any authenti… | |
| CVE-2026-42797 | Low | 0.4% | 4.9 | Exposure of Sensitive Information Through Data Queries vulnerability in Apache S… | |
| CVE-2026-46718 | Low | 0.4% | 6.5 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection… | |
| CVE-2026-73237 | Low | 0.4% | 6.1 | XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apa… | |
| CVE-2026-73238 | Low | 0.4% | 6.1 | XSS vulnerability in code display in Apache Allura. This issue affects Apache A… | |
| CVE-2026-45192 | Low | 0.4% | 6.5 | A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apac… | |
| CVE-2026-63016 | Low | 0.4% | 5.3 | Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could af… | |
| CVE-2026-50629 | Low | 0.4% | 5.3 | The 'clientId' parameter from incoming HTTP requests is directly concatenated in… | |
| CVE-2026-67591 | Low | 0.4% | 6.5 | An authenticated attacker could exceed the session flow control incoming window … | |
| CVE-2026-66275 | Low | 0.4% | 6.5 | An authenticated attacker could exceed the session flow control incoming window … | |
| CVE-2026-66276 | Low | 0.4% | 6.5 | An authenticated attacker can craft a disposition frame with large or illegal ra… | |
| CVE-2026-66277 | Low | 0.4% | 6.5 | It was not possible to govern the maximum number of transfer frames per incoming… | |
| CVE-2026-68075 | Low | 0.4% | 6.5 | An authenticated attacker could exceed the session flow control incoming window … | |
| CVE-2026-68077 | Low | 0.4% | 6.5 | An authenticated attacker can craft a disposition frame with large or illegal ra… | |
| CVE-2026-68080 | Low | 0.4% | 6.5 | It was not possible to govern the rate at which the broker would respond to an e… | |
| CVE-2026-45812 | Low | 0.4% | 6.5 | Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when process… | |
| CVE-2026-59230 | Low | 0.4% | 6.5 | Improper input validation vulnerability in Apache Camel. This issue affects A… | |
| CVE-2026-84439 | Low | 0.4% | 5.3 | When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated … | |
| CVE-2026-58160 | Low | 0.4% | 6.5 | Apache Traffic Server reads out of bounds while parsing DNS answers. This issue… | |
| CVE-2026-23985 | Low | 0.4% | 6.5 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Su… | |
| CVE-2026-42526 | Low | 0.4% | 5.3 | In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-a… | |
| CVE-2026-67553 | Low | 0.4% | 6.5 | An authenticated attacker could exceed the session flow control incoming window … | |
| CVE-2026-67554 | Low | 0.4% | 6.5 | An authenticated attacker can craft a disposition frame with large or illegal ra… | |
| CVE-2026-67555 | Low | 0.4% | 6.5 | It was not possible to govern the maximum number of transfer frames per incoming… | |
| CVE-2026-68078 | Low | 0.4% | 6.5 | It was not possible to govern the maximum number of transfer frames per incoming… | |
| CVE-2026-75880 | Low | 0.4% | 6.5 | An authenticated client could attach a consumer with a selector containing craft… | |
| CVE-2026-43827 | Low | 0.4% | 6.5 | Default configurations of Apache Shiro have a session fixation vulnerability. T… | |
| CVE-2026-25688 | Low | 0.4% | 6.1 | Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. … | |
| CVE-2026-25699 | Low | 0.4% | 6.1 | Exposure of Private Personal Information to an Unauthorized Actor vulnerability … | |
| CVE-2026-84501 | Low | 0.4% | 5.3 | An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooK… | |
| CVE-2026-66391 | Low | 0.4% | 6.5 | Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability … | |
| CVE-2026-49296 | Low | 0.4% | 6.5 | Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose th… | |
| CVE-2026-58183 | Low | 0.4% | 5.9 | The Apache Traffic Server prefetch plugin can crash when processing attacker-inf… | |
| CVE-2026-65017 | Low | 0.4% | 6.5 | Apache Airflow's Config API did not mask team-scoped sensitive configuration val… | |
| CVE-2026-48726 | Low | 0.4% | 6.5 | A bug in Apache Airflow's auth manager logout handling left previously-issued JW… | |
| CVE-2026-33930 | Low | 0.4% | 5.9 | Apache Traffic Server copies the client Host header into a fixed-size stack buff… | |
| CVE-2026-61487 | Low | 0.4% | 6.5 | Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ … | |
| CVE-2026-63015 | Low | 0.4% | 4.3 | Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template r… | |
| CVE-2026-64640 | Low | 0.4% | 6.5 | Apache Polaris did not consistently validate storage locations supplied during t… | |
| CVE-2026-49270 | Low | 0.4% | 5.9 | Exposure of Sensitive Information Through Metadata vulnerability in Apache Activ… | |
| CVE-2026-44598 | Low | 0.4% | 5.4 | With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'… | |
| CVE-2026-41014 | Low | 0.4% | 4.3 | The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level a… | |
| CVE-2026-46764 | Low | 0.4% | 4.3 | The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache A… | |
| CVE-2026-23981 | Low | 0.4% | 4.3 | An Improper Authorization vulnerability exists in Apache Superset allowing an au… | |
| CVE-2026-34031 | Low | 0.4% | 6.5 | Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. … | |
| CVE-2026-44613 | Low | 0.4% | 6.1 | Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default … | |
| CVE-2026-50630 | Low | 0.4% | 6.5 | A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. Wh… | |
| CVE-2026-65945 | Low | 0.4% | 6.5 | Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are … |