Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2026-49875 Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointReferenceUtils — Apache CXF CWE-611 - - 2026-06-12
CVE-2026-50623 Apache CXF: Authentication Bypass in OAuth2 TokenIntrospectionService — Apache CXF CWE-287 - - 2026-06-12
CVE-2026-47342 Apache OFBiz: Privilege Escalation via updateOrRemove Authorization Bypass — Apache OFBiz CWE-285 - - 2026-06-10
CVE-2026-50223 Apache OFBiz: DataResource Low-Privileged Authenticated FreeMarker Template Injection Leads to Remote Code Execution — Apache OFBiz CWE-94 - - 2026-06-10
CVE-2026-25700 Apache Answer: AdminToken not invalidated after admin deactivation — Apache Answer CWE-1259 - - 2026-06-10
CVE-2026-49818 Apache Airflow Samba provider: Path traversal in GCSToSambaOperator via GCS object names — Apache Airflow Samba provider CWE-22 - - 2026-06-09
CVE-2026-34905 Apache Answer: Unlisted Questions Accessible via Direct API Access — Apache Answer CWE-200 - - 2026-06-09
CVE-2026-34033 Apache Answer: HTML Content Injection in Email — Apache Answer CWE-80 - - 2026-06-09
CVE-2026-34031 Apache Answer: The custom avatar was not properly validated — Apache Answer CWE-434 - - 2026-06-09
CVE-2026-33582 Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory error — Apache Answer CWE-434 - - 2026-06-09
CVE-2026-25699 Apache Answer: Authorization Bypass in Timeline API — Apache Answer CWE-359 - - 2026-06-09
CVE-2026-25688 Apache Answer: XSS in AI Answer Rendering — Apache Answer CWE-87 - - 2026-06-09
CVE-2026-49975 Apache HTTP Server: mod_http2 denial of service — Apache HTTP Server CWE-789 - - 2026-06-08
CVE-2026-48913 Apache HTTP Server: mod_http2 memory corruption when file handles exhausted — Apache HTTP Server CWE-416 - - 2026-06-08
CVE-2026-42536 Apache HTTP Server: mod_xml2enc heap overflow — Apache HTTP Server CWE-122 - - 2026-06-08
CVE-2026-44185 Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request` — Apache HTTP Server CWE-126 - - 2026-06-08
CVE-2026-34355 Apache HTTP Server: mod_proxy_html buffer overflow — Apache HTTP Server CWE-122 - - 2026-06-08
CVE-2026-44631 Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow — Apache HTTP Server CWE-124 - - 2026-06-08
CVE-2026-44119 Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules — Apache HTTP Server CWE-269 - - 2026-06-08
CVE-2026-43951 Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash — Apache HTTP Server CWE-125 - - 2026-06-08
CVE-2026-42535 Apache HTTP Server: mod_dav_fs protected directory access — Apache HTTP Server CWE-668 - - 2026-06-08
CVE-2026-34356 Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow — Apache HTTP Server CWE-122 - - 2026-06-08
CVE-2026-44186 Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp — Apache HTTP Server CWE-835 - - 2026-06-08
CVE-2026-29170 Apache HTTP Server: mod_proxy_ftp XSS — Apache HTTP Server CWE-79 - - 2026-06-08
CVE-2026-29167 Apache HTTP Server: mod_ldap per-dir use-after-free — Apache HTTP Server CWE-416 - - 2026-06-08
CVE-2026-47430 Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews — Cordova Plugin InAppBrowser CWE-20 - - 2026-06-08
CVE-2026-50076 Apache Fory: Java ReplaceResolverSerializer deserialization checks bypass — Apache Fory CWE-502 - - 2026-06-04
CVE-2026-47065 Apache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClass - ZDRES-232 — Apache MINA CWE-502 9.8 Critical 2026-06-03
CVE-2026-46718 Apache Calcite: A user-controled model can load arbitrary classes, leading to code execution — Apache Calcite CWE-470 - - 2026-06-02
CVE-2026-41115 Apache Kafka: Improper Authorization in CONSUMER_GROUP_DESCRIBE API — Apache Kafka CWE-285 - - 2026-06-02

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.