Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2345

Browse all 2345 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2026-61372 Apache Jena Fuseki: Web requests using SPARQL Update can escape file restrictions — Apache Jena Fuseki CWE-22 - - 2026-08-03
CVE-2026-44615 Path traversal in NotebookRepo note and folder path composition — Apache Zeppelin CWE-22 - - 2026-07-31
CVE-2026-64607 Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS — Apache HttpComponents Client CWE-772 - - 2026-07-31
CVE-2026-62391 Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases — Apache Kyuubi CWE-22 - - 2026-07-31
CVE-2026-66756 Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false — Apache Tika CWE-424 6.9 Medium 2026-07-30
CVE-2026-66755 Apache Tika: Arbitrary Local File Read in ISArchiveParser — Apache Tika CWE-22 5.9 Medium 2026-07-30
CVE-2026-23985 Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser — Apache Superset CWE-1333 5.3 Medium 2026-07-30
CVE-2026-23981 Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modification — Apache Superset CWE-285 5.3 Medium 2026-07-30
CVE-2026-52680 Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write — Apache Kyuubi CWE-22 - - 2026-07-30
CVE-2026-48910 Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing — Apache JSPWiki CWE-80 - - 2026-07-30
CVE-2026-28814 Apache JSPWiki: Pre-Authentication Arbitrary Wiki Markup Rendering — Apache JSPWiki - - 2026-07-30
CVE-2026-28813 Apache JSPWiki: JSPWiki vulnerable to JSON hijacking — Apache JSPWiki CWE-352 - - 2026-07-30
CVE-2026-28812 Apache JSPWiki: UserManager does not sanity-check user database at startup — Apache JSPWiki - - 2026-07-30
CVE-2026-28811 Apache JSPWiki: Error Handling - Reveals Error Details — Apache JSPWiki CWE-1295 - - 2026-07-30
CVE-2026-44617 Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867 — Apache Zeppelin CWE-90 - - 2026-07-30
CVE-2026-44616 Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction — Apache Zeppelin CWE-90 - - 2026-07-30
CVE-2026-44613 Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling — Apache Zeppelin CWE-352 - - 2026-07-30
CVE-2026-50622 Apache Atlas: Missing Authorization on Admin Endpoints — Apache Atlas CWE-862 - - 2026-07-29
CVE-2026-23904 Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy — Apache Kyuubi CWE-923 - - 2026-07-29
CVE-2026-65100 Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header encode — Apache Traffic Server CWE-696 4.8 Medium 2026-07-29
CVE-2026-58189 Apache Traffic Server: Plugins resetting the redirect counter enable SSRF amplification — Apache Traffic Server CWE-918 7.5 High 2026-07-29
CVE-2026-58188 Apache Traffic Server: Memory-safety and limit-bypass errors across experimental plugins — Apache Traffic Server CWE-787 8.2 High 2026-07-29
CVE-2026-58187 Apache Traffic Server: Multiplexer plugin chunk decoder enables a denial of service — Apache Traffic Server CWE-787 3.7 Low 2026-07-29
CVE-2026-58186 Apache Traffic Server: webp_transform plugin decodes unsafely and mislabels degraded responses — Apache Traffic Server CWE-20 7.5 High 2026-07-29
CVE-2026-58185 Apache Traffic Server: Use-after-free in the intercept plugin — Apache Traffic Server CWE-416 5.9 Medium 2026-07-29
CVE-2026-58184 Apache Traffic Server: header_rewrite plugin cookie handling can corrupt memory — Apache Traffic Server CWE-787 8.2 High 2026-07-29
CVE-2026-58183 Apache Traffic Server: prefetch plugin can crash on attacker-influenced input — Apache Traffic Server CWE-20 5.9 Medium 2026-07-29
CVE-2026-58182 Apache Traffic Server: ts_lua plugin has initialization and resource-handling errors — Apache Traffic Server CWE-400 8.6 High 2026-07-29
CVE-2026-58181 Apache Traffic Server: uri_signing and url_sig plugins can exhaust the stack or crash — Apache Traffic Server CWE-121 7.5 High 2026-07-29
CVE-2026-58180 Apache Traffic Server: txn_box plugin overflows the stack from attacker input — Apache Traffic Server CWE-121 7.5 High 2026-07-29

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.