An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker to access internal metadata service endpoints. The affected endpoints relied on client-supplied node information for authenticatio
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Doris | 2.0.0 ~ 4.0.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76183 | Apache Tomcat: Bypass of security constraints for WebSocket endpoints | |
| CVE-2026-82331 | Apache BuildStream: tar source extraction escape | |
| CVE-2026-73192 | Apache Sling XSS: XSS possible through XSSAPI.getValidHref() | |
| CVE-2026-92001 | Apache Sling XSS: Missing parser resource limits | |
| CVE-2026-91999 | Apache Sling XSS: Improper escaping in the XSS Webconsole plugin | |
| CVE-2026-91852 | Apache Sling XSS: CWE-79 multiple raw-string break-outs and ReDOS in XSSImpl | |
| CVE-2026-96443 | Apache Doris: JDBC driver URL validation bypass leads to remote code execution | |
| CVE-2026-91928 | Apache Sling XSS: Sanitizer bypass, uncontrolled resource consumption and failure pf prote | |
| CVE-2026-94251 | Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape | |
| CVE-2026-94243 | Apache Sling Security Bundle: RefererFilter accepts weaker-than-origin evidence | |
| CVE-2026-73581 | Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate us | |
| CVE-2026-75973 | Apache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configured | |
| CVE-2026-86247 | Apache Tomcat Native: Client certificate requirements can be down-graded | |
| CVE-2026-77756 | Apache Tomcat: Transfer-Encoding honored for HTTP/1.0 requests | |
| CVE-2026-77762 | Apache Tomcat: Stale HPACK emitter injects trailers into recycled pooled Request | |
| CVE-2026-77791 | Apache Tomcat: DoS via busy wait during WebSocket close | |
| CVE-2026-78383 | Apache Tomcat: AJP DoS via missing request body | |
| CVE-2026-78437 | Apache Tomcat: HTTP/2 DoS via malformed request | |
| CVE-2026-79677 | Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout | |
| CVE-2026-86248 | Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with |
Showing top 20 of 25 CVEs. View all on vendor page → →
No comments yet