Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2026-40008 Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC — Apache IoTDB CWE-470 - - 2026-07-10
CVE-2026-40007 Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError — Apache IoTDB CWE-674 - - 2026-07-10
CVE-2026-40006 Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver — Apache IoTDB CWE-789 - - 2026-07-10
CVE-2026-40005 Apache IoTDB: Path Traversal in Pipe File Transfer Receiver — Apache IoTDB CWE-22 - - 2026-07-10
CVE-2026-28564 Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials — Apache IoTDB CWE-613 - - 2026-07-10
CVE-2026-57111 Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-Origin — Apache Helix REST CWE-1385 - - 2026-07-09
CVE-2026-41042 Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter — Apache Gravitino CWE-20 - - 2026-07-08
CVE-2026-33264 Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize() — Apache Airflow CWE-502 - - 2026-07-07
CVE-2026-49487 Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs — Apache Airflow CWE-200 - - 2026-07-07
CVE-2026-48828 Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key — Apache Airflow CWE-200 - - 2026-07-07
CVE-2026-49296 Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagSources/{dag_id} — Apache Airflow CWE-639 - - 2026-07-07
CVE-2026-48891 Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.target — Apache Airflow CWE-200 - - 2026-07-07
CVE-2026-48892 Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic options — Apache Airflow CWE-200 - - 2026-07-07
CVE-2026-43825 Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel — Apache OpenNLP :: Core :: ML :: LibSVM CWE-502 - - 2026-07-06
CVE-2026-49297 Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator) — Apache Airflow Google provider CWE-22 - - 2026-07-06
CVE-2026-46588 Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input — Apache Camel CWE-20 - - 2026-07-06
CVE-2026-46587 Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input — Apache Camel CWE-20 - - 2026-07-06
CVE-2026-49042 Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters — Apache Camel CWE-20 - - 2026-07-06
CVE-2026-24013 Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC — Apache IoTDB CWE-290 - - 2026-07-06
CVE-2026-24012 Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query — Apache IoTDB CWE-400 - - 2026-07-06
CVE-2026-43866 Apache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder — Apache Camel CWE-502 - - 2026-07-06
CVE-2026-24014 Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write — Apache IoTDB CWE-284 - - 2026-07-06
CVE-2026-43867 Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter — Apache Camel CWE-502 - - 2026-07-06
CVE-2026-56140 Apache Camel AWS2 SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy to align it with sibling components — Apache Camel AWS2 SNS CWE-20 - - 2026-07-06
CVE-2026-56139 Apache Camel Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients — Apache Camel Undertow CWE-209 - - 2026-07-06
CVE-2026-55994 Apache Camel Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling control over internal behaviour — Apache Camel Iggy CWE-20 - - 2026-07-06
CVE-2026-55993 Apache Camel Atmosphere Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling influencing internal behaviour — Apache Camel Atmosphere Websocket CWE-20 - - 2026-07-06
CVE-2026-53913 Apache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default configuration the token is never verified and any non-null bearer value is accepted — Apache Camel Keycloak CWE-287 - - 2026-07-06
CVE-2026-49365 Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients — Apache Camel CWE-209 - - 2026-07-06
CVE-2026-49099 Apache Camel Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour — Apache Camel Salesforce CWE-74 - - 2026-07-06

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.