Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2345

Browse all 2345 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2026-70410 Apache Calcite Avatica: Unrestricted class initialization when instantiating plugins — Apache Calcite Avatica CWE-470 - - 2026-09-22
CVE-2026-94301 Apache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.X branches (2.0.30 / 2.1.14) ZDRES-232 — Apache MINA CWE-502 9.8 Critical 2026-09-21
CVE-2026-86473 Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocable only by expiry — Apache Airflow CWE-613 - - 2026-09-21
CVE-2026-75158 Apache Airflow: Assets events API returns asset events for every Dag with no per-Dag authorization filter — Apache Airflow CWE-200 - - 2026-09-21
CVE-2026-82355 Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, enabling session fixation — Apache Airflow CWE-384 - - 2026-09-21
CVE-2026-91867 Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitely — Apache Neethi - - 2026-09-21
CVE-2026-91866 Apache Neethi: Crafted policies cause unbounded work during intersection leading to denial of service — Apache Neethi - - 2026-09-21
CVE-2026-91865 Apache Neethi: Crafted policy references cause exponential expansion during normalization leading to denial of service — Apache Neethi - - 2026-09-21
CVE-2026-91864 Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustion — Apache Neethi - - 2026-09-21
CVE-2026-91863 Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows denial of service — Apache Neethi - - 2026-09-21
CVE-2026-47321 Apache MINA: Unbounded Decompression Amplification DoS in Zlib.inflate — Apache MINA CWE-409 7.5 High 2026-09-21
CVE-2026-75157 Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDIT (asset-triggered scheduling suppression) — Apache Airflow CWE-863 - - 2026-09-18
CVE-2026-92230 Apache Karaf: Improper release of ClassLoader references via static ThreadLocal caching — Apache Karaf CWE-401 - - 2026-09-17
CVE-2026-70469 Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests — Apache NiFi CWE-409 - - 2026-09-16
CVE-2026-81866 Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration — Apache NiFi CWE-862 0.5 Low 2026-09-16
CVE-2026-82561 Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods — Apache NiFi CWE-862 5.9 Medium 2026-09-16
CVE-2026-86089 Apache NiFi: Missing Process Group Authorization for Connector Migration — Apache NiFi CWE-862 2.3 Low 2026-09-16
CVE-2026-87976 Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles — Apache NiFi Registry CWE-22 7.2 High 2026-09-16
CVE-2026-76646 Apache MyFaces: Denial of Service via Unbounded Request Parsing — Apache MyFaces CWE-400 - - 2026-09-16
CVE-2026-68536 Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability — Apache MyFaces CWE-918 - - 2026-09-16
CVE-2026-84501 Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationProvider — Apache ZooKeeper CWE-117 - - 2026-09-16
CVE-2026-84439 Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources — Apache ZooKeeper CWE-117 - - 2026-09-16
CVE-2026-79993 Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znode — Apache ZooKeeper CWE-862 - - 2026-09-16
CVE-2026-59969 Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode — Apache ZooKeeper CWE-297 - - 2026-09-16
CVE-2026-59739 Apache ZooKeeper: Information disclosure via SetWatches reconnect replay — Apache ZooKeeper CWE-862 - - 2026-09-16
CVE-2026-86466 Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validated — Apache Airflow FAB provider CWE-346 - - 2026-09-16
CVE-2026-76187 Apache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session JWT — Apache Airflow Keycloak provider CWE-287 - - 2026-09-16
CVE-2026-76186 Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity — Apache Airflow Keycloak provider CWE-565 - - 2026-09-16
CVE-2026-82310 Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access — Apache Airflow FAB provider CWE-613 - - 2026-09-16
CVE-2026-86792 Apache Airflow Apache Kafka provider: Connection-editor remote code execution on the Scheduler via Kafka connection callback configuration — Apache Airflow Apache Kafka provider CWE-470 - - 2026-09-16

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.