Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1676

Browse all 1676 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2026-40557 Apache Storm Prometheus Reporter: Disabling TLS verification for Prometheus Reporter also disables it for all other connections — Apache Storm Prometheus ReporterCWE-295--2026-04-27
CVE-2026-41081 Apache Storm Client: Anonymous principal assigned on TLS client certificate verification failure — Apache Storm ClientCWE-287--2026-04-27
CVE-2026-27172 Apache Camel: Unsafe Java deserialization in camel-consul ConsulRegistry allows arbitrary code execution via malicious values read from the Consul KV store — Apache CamelCWE-502--2026-04-27
CVE-2026-33453 Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution — Apache CamelCWE-915--2026-04-27
CVE-2026-33454 Apache Camel: Inbound Header Filter Missing in MailHeaderFilterStrategy Allows Remote Code Execution via MIME Header Injection (CVE-2025-30177 Variant) — Apache CamelCWE-502--2026-04-27
CVE-2026-40022 Apache Camel Platform HTTP Main: Authentication Bypass on Non-Root Context Paths in camel main runtime — Apache Camel Platform HTTP MainCWE-288--2026-04-27
CVE-2026-40858 Apache Camel: Camel-Infinispan: Unsafe Deserialization in Remote Aggregation Repository — Apache CamelCWE-502--2026-04-27
CVE-2026-41409 Apache MINA: CWE-502 Deserialization of Untrusted Data — Apache MINACWE-502 9.8 Critical2026-04-27
CVE-2026-41635 Apache MINA: AbstractIoBuffer.resolveClass() null-clazz Branch Skips acceptMatchers Filter — Full Object Deserialization RCE — Apache MINACWE-502 9.8 Critical2026-04-27
CVE-2026-40453 Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, camel-coap, camel-google-pubsub) allows case-variant header injection — Apache Camel JMSCWE-178--2026-04-27
CVE-2026-40860 Apache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqp — Apache CamelCWE-502--2026-04-27
CVE-2026-40048 Apache Camel PQC: Unsafe Deserialization from FileBasedKeyLifecycleManager — Apache Camel PQCCWE-502--2026-04-27
CVE-2026-40473 Apache Camel Mina: Unsafe Deserialization in MinaConverter.toObjectInput() via TCP/UDP — Apache Camel MinaCWE-502--2026-04-27
CVE-2026-38743 Apache Airflow: Dags endpoint might provide access to otherwise inaccessible entities — Apache AirflowCWE-1220 4.3AIMediumAI2026-04-24
CVE-2026-40690 Apache Airflow: Assets graph view bypasses DAG level access control displaying unrelated topologies and all DAGs names to unauthorized users — Apache AirflowCWE-1220 4.3AIMediumAI2026-04-24
CVE-2026-23902 Apache DolphinScheduler: Users are able to use tenants that are not defined on the platform during workflow execution. — Apache DolphinSchedulerCWE-863 8.8AIHighAI2026-04-24
CVE-2025-62233 Apache DolphinScheduler: Deserialization of untrusted data in RPC — Apache DolphinSchedulerCWE-502 8.8AIHighAI2026-04-24
CVE-2026-41044 Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia — Apache ActiveMQCWE-20 7.2AIHighAI2026-04-24
CVE-2026-41043 Apache ActiveMQ, Apache ActiveMQ Web: ActiveMQ Web Console - XSS vulnerability when browsing queues — Apache ActiveMQCWE-79 5.4AIMediumAI2026-04-24
CVE-2026-40466 Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI — Apache ActiveMQ BrokerCWE-20 8.8AIHighAI2026-04-24
CVE-2026-40542 Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to accept authentication without proper mutual authentication verification — Apache HttpClientCWE-304 9.1AICriticalAI2026-04-22
CVE-2026-33557 Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication — Apache KafkaCWE-1285 9.1AICriticalAI2026-04-20
CVE-2025-66335 Apache Doris MCP Server: MCP SQL inject — Apache Doris MCP ServerCWE-89 9.8AICriticalAI2026-04-20
CVE-2026-33558 Apache Kafka, Apache Kafka Clients: Information Exposure Through Network Client Log Output — Apache KafkaCWE-533 5.9AIMediumAI2026-04-20
CVE-2026-40948 Apache Airflow Providers Keycloak: OAuth Login CSRF — Missing State Parameter in Keycloak Auth Manager — Apache Airflow Providers KeycloakCWE-352 7.3AIHighAI2026-04-18
CVE-2026-32690 Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1 — Apache AirflowCWE-668 7.5AIHighAI2026-04-18
CVE-2026-30898 Apache Airflow: Bad example of BashOperator shell injection via dag_run.conf — Apache AirflowCWE-77 8.8AIHighAI2026-04-18
CVE-2026-30912 Apache Airflow: Exposing stack trace in case of constraint error — Apache AirflowCWE-668 7.5AIHighAI2026-04-18
CVE-2026-25917 Apache Airflow: API extra-links triggers XCom deserialization/class instantiation (Airflow 3.1.5) — Apache AirflowCWE-502 9.8AICriticalAI2026-04-18
CVE-2026-32228 Apache Airflow: Users with asset materialization permisssions could trigger Dags they had no access to — Apache AirflowCWE-863 7.1AIHighAI2026-04-18

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.