Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2345

Browse all 2345 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2026-54428 Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK — Apache HttpComponents Core CWE-770 - - 2026-07-01
CVE-2026-54399 Apache HttpComponents Core: Unbounded HTTP Header/Line Length in Default Configuration — Apache HttpComponents Core CWE-400 - - 2026-07-01
CVE-2025-53648 Apache Gravitino: SQL misconfiguration can access or truncate files — Apache Gravitino CWE-89 - - 2026-06-30
CVE-2026-49434 Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: LdapNetworkConnector instantiates denied transports and a remote-properties broker — Apache ActiveMQ Broker CWE-20 - - 2026-06-30
CVE-2026-49432 Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative content-length enables denial of service — Apache ActiveMQ CWE-20 - - 2026-06-30
CVE-2026-49877 Apache ActiveMQ: Authenticated web users retain admin access by default in the Web Console — Apache ActiveMQ CWE-285 - - 2026-06-30
CVE-2026-50734 Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire memory-allocation DoS during wire format negotiation — Apache ActiveMQ Client CWE-789 - - 2026-06-30
CVE-2026-50750 Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire DoS following fix for CVE-2026-49270 — Apache ActiveMQ Broker - - 2026-06-30
CVE-2026-52760 Apache ActiveMQ, Apache ActiveMQ Web Console: Stored XSS via Unescaped values in ActiveMQ Web Console — Apache ActiveMQ CWE-79 - - 2026-06-30
CVE-2026-53916 Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec — Apache ActiveMQ CWE-789 - - 2026-06-30
CVE-2026-53917 Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: Unbounded memory allocation in OpenWire property unmarshalling — Apache ActiveMQ CWE-789 - - 2026-06-30
CVE-2026-54475 Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary destination ownership takeover — Apache ActiveMQ Broker CWE-862 - - 2026-06-30
CVE-2026-55957 Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind — Apache Tomcat CWE-304 - - 2026-06-29
CVE-2026-55956 Apache Tomcat: Security constraints for default servlet ignored method — Apache Tomcat CWE-285 - - 2026-06-29
CVE-2026-55955 Apache Tomcat: EncryptInterceptor not protected against replay attacks — Apache Tomcat CWE-287 - - 2026-06-29
CVE-2026-55276 Apache Tomcat: Logged effective web.xml is incomplete — Apache Tomcat CWE-670 - - 2026-06-29
CVE-2026-53434 Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector — Apache Tomcat CWE-390 - - 2026-06-29
CVE-2026-53404 Apache Tomcat: Bad ornext processing in RewriteValve — Apache Tomcat CWE-670 - - 2026-06-29
CVE-2026-50229 Apache Tomcat: XSS in number guess example — Apache Tomcat CWE-80 - - 2026-06-29
CVE-2025-64152 Apache IoTDB: Path Traversal Vulnerability — Apache IoTDB CWE-22 - - 2026-06-26
CVE-2025-55017 Apache IoTDB: Path Traversal Vulnerability — Apache IoTDB CWE-22 - - 2026-06-26
CVE-2026-57915 Apache Kerby: Kerberos Pre-Authentication Bypass — Apache Kerby CWE-304 - - 2026-06-26
CVE-2026-57914 Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures — Apache Kerby CWE-400 - - 2026-06-26
CVE-2026-49486 Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing PROT_P) — Apache Airflow FTP provider CWE-319 - - 2026-06-26
CVE-2026-56091 Apache Shiro: Authentication bypass in Guice-Web integration — Apache Shiro CWE-289 - - 2026-06-25
CVE-2026-56130 Apache Shiro: Remember-me cookie isn't checked for expiry on the server — Apache Shiro CWE-294 - - 2026-06-25
CVE-2026-41566 Apache Kvrocks: Improper permission for the APPLYBATCH command — Apache Kvrocks CWE-280 - - 2026-06-25
CVE-2026-45188 Apache Kvrocks: Replication Fullsync Path Traversal via Unvalidated Filename Handling — Apache Kvrocks CWE-23 - - 2026-06-25
CVE-2026-46751 Apache Kvrocks: Does not remove the unsafe loadstring function from its Lua sandbox, allowing a user who can run EVAL scripts to load crafted, unvalidated bytecode that crashes the server process, resulting in a remote denial of service. — Apache Kvrocks - - 2026-06-25
CVE-2026-46752 Apache Kvrocks: Stack buffer overflow in Lua bit.tohex() — Apache Kvrocks CWE-122 - - 2026-06-25

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.