Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2345

Browse all 2345 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2026-49876 Apache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs — Apache Gravitino CWE-918 - - 2026-07-13
CVE-2026-49844 Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson() — Apache Log4j API CWE-116 6.3 Medium 2026-07-10
CVE-2026-40454 Apache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server data — Apache IoTDB C++ client CWE-125 - - 2026-07-10
CVE-2026-40452 Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users — Apache IoTDB CWE-863 - - 2026-07-10
CVE-2026-40009 Apache IoTDB: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor — Apache IoTDB CWE-269 - - 2026-07-10
CVE-2026-40008 Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC — Apache IoTDB CWE-470 - - 2026-07-10
CVE-2026-40007 Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError — Apache IoTDB CWE-674 - - 2026-07-10
CVE-2026-40006 Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver — Apache IoTDB CWE-789 - - 2026-07-10
CVE-2026-40005 Apache IoTDB: Path Traversal in Pipe File Transfer Receiver — Apache IoTDB CWE-22 - - 2026-07-10
CVE-2026-28564 Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials — Apache IoTDB CWE-613 - - 2026-07-10
CVE-2026-57111 Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-Origin — Apache Helix REST CWE-1385 - - 2026-07-09
CVE-2026-41042 Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter — Apache Gravitino CWE-20 - - 2026-07-08
CVE-2026-33264 Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize() — Apache Airflow CWE-502 - - 2026-07-07
CVE-2026-49487 Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs — Apache Airflow CWE-200 - - 2026-07-07
CVE-2026-48828 Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key — Apache Airflow CWE-200 - - 2026-07-07
CVE-2026-49296 Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagSources/{dag_id} — Apache Airflow CWE-639 - - 2026-07-07
CVE-2026-48891 Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.target — Apache Airflow CWE-200 - - 2026-07-07
CVE-2026-48892 Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic options — Apache Airflow CWE-200 - - 2026-07-07
CVE-2026-43825 Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel — Apache OpenNLP :: Core :: ML :: LibSVM CWE-502 - - 2026-07-06
CVE-2026-49297 Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator) — Apache Airflow Google provider CWE-22 - - 2026-07-06
CVE-2026-46588 Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input — Apache Camel CWE-20 - - 2026-07-06
CVE-2026-46587 Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input — Apache Camel CWE-20 - - 2026-07-06
CVE-2026-49042 Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters — Apache Camel CWE-20 - - 2026-07-06
CVE-2026-24013 Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC — Apache IoTDB CWE-290 - - 2026-07-06
CVE-2026-24012 Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query — Apache IoTDB CWE-400 - - 2026-07-06
CVE-2026-43866 Apache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder — Apache Camel CWE-502 - - 2026-07-06
CVE-2026-24014 Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write — Apache IoTDB CWE-284 - - 2026-07-06
CVE-2026-43867 Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter — Apache Camel CWE-502 - - 2026-07-06
CVE-2026-56140 Apache Camel AWS2 SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy to align it with sibling components — Apache Camel AWS2 SNS CWE-20 - - 2026-07-06
CVE-2026-56139 Apache Camel Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients — Apache Camel Undertow CWE-209 - - 2026-07-06

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.