Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2345

Browse all 2345 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2026-86462 Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessions — Apache Airflow FAB provider CWE-613 - - 2026-09-16
CVE-2026-82311 Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int _user_id comparison is always false — Apache Airflow FAB provider CWE-613 - - 2026-09-16
CVE-2026-86465 Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard bypass via user-controlled key — Apache Airflow Akeyless provider CWE-639 - - 2026-09-16
CVE-2026-82427 Apache Storm Nimbus: Path Traversal as the Supervisor User via Unsanitised Blobstore Map Local Name — Apache Storm Nimbus CWE-22 - - 2026-09-14
CVE-2026-82428 Apache Storm Client: Cross-Tenant Dependency Jar Substitution via Predictable Blob Keys — Apache Storm Client CWE-22 - - 2026-09-14
CVE-2026-82429 Apache Storm Worker Launcher: Local Privilege Escalation to Root via a Time-of-Check Race in the Worker Launcher — Apache Storm Worker Launcher CWE-367 - - 2026-09-14
CVE-2026-82430 Apache Storm Worker Launcher: Local Privilege Escalation to Root via Container Command Files Chowned to the Tenant — Apache Storm Worker Launcher CWE-367 - - 2026-09-14
CVE-2026-82431 Apache Storm Client: Authorization Bypass When nimbus.groups Is Configured Without nimbus.users — Apache Storm Client CWE-863 - - 2026-09-14
CVE-2026-82433 Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Daemon Configuration via Nimbus and the UI — Apache Storm Nimbus CWE-522 - - 2026-09-14
CVE-2026-82432 Apache Storm Nimbus: Blobstore Authorization Bypass via Rebalance Configuration Overrides — Apache Storm Nimbus CWE-863 - - 2026-09-14
CVE-2026-82434 Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs — Apache Storm Nimbus CWE-522 10.0 Critical 2026-09-14
CVE-2026-82435 Apache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker Messaging Decoder — Apache Storm Worker CWE-789 - - 2026-09-14
CVE-2026-82437 Apache Storm Logviewer: Log Access Controls Not Enforced by Logviewer — Apache Storm Logviewer CWE-862 - - 2026-09-14
CVE-2026-82426 Apache Storm Nimbus: Arbitrary File Read on Nimbus via Unvalidated Uploaded Jar Location — Apache Storm Nimbus CWE-22 - - 2026-09-14
CVE-2026-82438 Apache Storm Webapp: Authenticated API Responses Exposed to Arbitrary Web Origins — Apache Storm Webapp CWE-346 - - 2026-09-14
CVE-2026-82439 Apache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPC — Apache Storm DRPC CWE-770 - - 2026-09-14
CVE-2026-82441 Apache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service via Unvalidated Topology Dependency Keys — Apache Storm Nimbus CWE-20 - - 2026-09-14
CVE-2026-84179 Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Merged Daemon Configuration via the Topology Page — Apache Storm Nimbus CWE-522 - - 2026-09-14
CVE-2026-73191 Apache Syncope: CAS service URL injection via Forwarded HTTP headers — Apache Syncope CWE-601 - - 2026-09-14
CVE-2026-73195 Apache Syncope: CSV export spreadsheet formula injection — Apache Syncope CWE-116 - - 2026-09-14
CVE-2026-73236 Apache Syncope: Cross-Realm authorization bypass in delegated administration — Apache Syncope CWE-863 - - 2026-09-14
CVE-2026-73370 Apache Syncope: Cross-Realm boundaries reconciliation bypass — Apache Syncope CWE-863 - - 2026-09-14
CVE-2026-73178 Apache Syncope: JWT Access Token takeover — Apache Syncope CWE-200 - - 2026-09-14
CVE-2026-73470 Apache Syncope: Delegating users can grant unowned Roles — Apache Syncope CWE-269 - - 2026-09-14
CVE-2026-73579 Apache Syncope: Non-recursive Any search could skip Realms restrictions — Apache Syncope CWE-863 - - 2026-09-14
CVE-2026-75015 Apache Syncope: Nested secrets leak cleartext into audit records readable — Apache Syncope CWE-522 - - 2026-09-14
CVE-2026-75030 Apache Syncope: Incomplete authorization checks for Group members deprovisioning — Apache Syncope CWE-862 - - 2026-09-14
CVE-2026-77051 Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search — Apache Syncope CWE-89 - - 2026-09-14
CVE-2026-73668 Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values — Apache Syncope CWE-863 - - 2026-09-14
CVE-2026-77147 Apache Syncope: Groovy Sandbox escape for empty CommandArgs — Apache Syncope CWE-94 - - 2026-09-14

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.