Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2345

Browse all 2345 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

Found 145 results / 2345 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-42360 Apache Airflow: Rendered template truncation bypasses nested sensitive-key masking — Apache Airflow CWE-200 - - 2026-06-01
CVE-2026-42358 Apache Airflow: Variable masker depth-limit bypass returns cleartext nested secrets — Apache Airflow CWE-200 - - 2026-06-01
CVE-2026-42359 Apache Airflow: Authenticated RCE via XCom PATCH endpoint — XComUpdateBody missing FORBIDDEN_XCOM_KEYS validator — Apache Airflow CWE-502 - - 2026-06-01
CVE-2026-45360 Apache Airflow: Arbitrary import in custom deadline-reference deserialization — Apache Airflow CWE-502 - - 2026-06-01
CVE-2026-45426 Apache Airflow: Log server JWT authorization bypass via Python lstrip() character stripping allows cross-Dag log access — Apache Airflow CWE-863 - - 2026-06-01
CVE-2026-46764 Apache Airflow: Event Log detail endpoint bypasses DAG-scoped event log permission filter — Apache Airflow CWE-639 - - 2026-06-01
CVE-2026-48726 Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logout path — Apache Airflow CWE-613 - - 2026-06-01
CVE-2026-49298 Apache Airflow: JWT Token Exposure in KubernetesExecutor Command-Line Arguments — Apache Airflow CWE-538 - - 2026-06-01
CVE-2026-45192 Apache Airflow: Incomplete Redaction of Sensitive Fields in Connection Extra API Response — Apache Airflow CWE-200 - - 2026-06-01
CVE-2026-38743 Apache Airflow: Dags endpoint might provide access to otherwise inaccessible entities — Apache Airflow CWE-1220 4.3AI Medium AI 2026-04-24
CVE-2026-40690 Apache Airflow: Assets graph view bypasses DAG level access control displaying unrelated topologies and all DAGs names to unauthorized users — Apache Airflow CWE-1220 4.3AI Medium AI 2026-04-24
CVE-2026-32690 Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1 — Apache Airflow CWE-668 7.5AI High AI 2026-04-18
CVE-2026-30898 Apache Airflow: Bad example of BashOperator shell injection via dag_run.conf — Apache Airflow CWE-77 8.8AI High AI 2026-04-18
CVE-2026-30912 Apache Airflow: Exposing stack trace in case of constraint error — Apache Airflow CWE-668 7.5AI High AI 2026-04-18
CVE-2026-25917 Apache Airflow: API extra-links triggers XCom deserialization/class instantiation (Airflow 3.1.5) — Apache Airflow CWE-502 9.8AI Critical AI 2026-04-18
CVE-2026-32228 Apache Airflow: Users with asset materialization permisssions could trigger Dags they had no access to — Apache Airflow CWE-863 7.1AI High AI 2026-04-18
CVE-2026-31987 Apache Airflow: JWT token appearing in logs — Apache Airflow CWE-532 6.5AI Medium AI 2026-04-16
CVE-2026-25219 Apache Airflow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access — Apache Airflow CWE-200 6.5 - 2026-04-15
CVE-2025-54550 Apache Airflow: RCE by race condition in example_xcom dag — Apache Airflow CWE-94 8.8 - 2026-04-15
CVE-2026-33858 Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API — Apache Airflow CWE-502 9.8 - 2026-04-13
CVE-2025-66236 Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI — Apache Airflow CWE-532 9.6 - 2026-04-13
CVE-2025-57735 Apache Airflow: Airflow Logout Not Invalidating JWT — Apache Airflow CWE-613 9.1AI Critical AI 2026-04-09
CVE-2026-34538 Apache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure) — Apache Airflow CWE-668 6.5AI Medium AI 2026-04-09
CVE-2026-28563 Apache Airflow: DAG authorization bypass — Apache Airflow CWE-732 4.3 - 2026-03-17
CVE-2026-26929 Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata — Apache Airflow CWE-732 5.3AI Medium AI 2026-03-17
CVE-2026-30911 Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization — Apache Airflow CWE-862 8.1AI High AI 2026-03-17
CVE-2026-28779 Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications — Apache Airflow CWE-668 9.8AI Critical AI 2026-03-17
CVE-2025-27555 Apache Airflow: Connection Secrets not masked in UI when Connection are added via Airflow cli — Apache Airflow CWE-532 6.5AI Medium AI 2026-02-24
CVE-2024-56373 Apache Airflow: SSTI to Code Execution in Airflow through Shared DB Information — Apache Airflow CWE-94 8.0AI High AI 2026-02-24
CVE-2025-65995 Apache Airflow: Disclosure of secrets to UI via kwargs — Apache Airflow CWE-209 6.5AI Medium AI 2026-02-21

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.