Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2026-41605 Apache Thrift: Swift Compact Protocol integer overflow — Apache Thrift CWE-190 9.8AI Critical AI 2026-04-28
CVE-2026-41604 Apache Thrift: Swift Range crash in skip() — Apache Thrift CWE-125 7.5AI High AI 2026-04-28
CVE-2026-41602 Apache Thrift: Go TFramedTransport uint32 overflow — Apache Thrift CWE-190 9.8AI Critical AI 2026-04-28
CVE-2025-48431 Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error. — Apache Thrift CWE-762 7.5AI High AI 2026-04-28
CVE-2026-40557 Apache Storm Prometheus Reporter: Disabling TLS verification for Prometheus Reporter also disables it for all other connections — Apache Storm Prometheus Reporter CWE-295 7.4AI High AI 2026-04-27
CVE-2026-41081 Apache Storm Client: Anonymous principal assigned on TLS client certificate verification failure — Apache Storm Client CWE-287 9.1AI Critical AI 2026-04-27
CVE-2026-27172 Apache Camel: Unsafe Java deserialization in camel-consul ConsulRegistry allows arbitrary code execution via malicious values read from the Consul KV store — Apache Camel CWE-502 8.8AI High AI 2026-04-27
CVE-2026-33453 Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution — Apache Camel CWE-915 9.8AI Critical AI 2026-04-27
CVE-2026-33454 Apache Camel: Inbound Header Filter Missing in MailHeaderFilterStrategy Allows Remote Code Execution via MIME Header Injection (CVE-2025-30177 Variant) — Apache Camel CWE-502 9.1AI Critical AI 2026-04-27
CVE-2026-40022 Apache Camel Platform HTTP Main: Authentication Bypass on Non-Root Context Paths in camel main runtime — Apache Camel Platform HTTP Main CWE-288 9.8AI Critical AI 2026-04-27
CVE-2026-40858 Apache Camel: Camel-Infinispan: Unsafe Deserialization in Remote Aggregation Repository — Apache Camel CWE-502 8.8AI High AI 2026-04-27
CVE-2026-41409 Apache MINA: CWE-502 Deserialization of Untrusted Data — Apache MINA CWE-502 9.8 Critical 2026-04-27
CVE-2026-41635 Apache MINA: AbstractIoBuffer.resolveClass() null-clazz Branch Skips acceptMatchers Filter — Full Object Deserialization RCE — Apache MINA CWE-502 9.8 Critical 2026-04-27
CVE-2026-40453 Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, camel-coap, camel-google-pubsub) allows case-variant header injection — Apache Camel JMS CWE-178 9.8AI Critical AI 2026-04-27
CVE-2026-40860 Apache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqp — Apache Camel CWE-502 9.8AI Critical AI 2026-04-27
CVE-2026-40048 Apache Camel PQC: Unsafe Deserialization from FileBasedKeyLifecycleManager — Apache Camel PQC CWE-502 8.8AI High AI 2026-04-27
CVE-2026-40473 Apache Camel Mina: Unsafe Deserialization in MinaConverter.toObjectInput() via TCP/UDP — Apache Camel Mina CWE-502 9.8AI Critical AI 2026-04-27
CVE-2026-38743 Apache Airflow: Dags endpoint might provide access to otherwise inaccessible entities — Apache Airflow CWE-1220 4.3AI Medium AI 2026-04-24
CVE-2026-40690 Apache Airflow: Assets graph view bypasses DAG level access control displaying unrelated topologies and all DAGs names to unauthorized users — Apache Airflow CWE-1220 4.3AI Medium AI 2026-04-24
CVE-2026-23902 Apache DolphinScheduler: Users are able to use tenants that are not defined on the platform during workflow execution. — Apache DolphinScheduler CWE-863 8.8AI High AI 2026-04-24
CVE-2025-62233 Apache DolphinScheduler: Deserialization of untrusted data in RPC — Apache DolphinScheduler CWE-502 8.8AI High AI 2026-04-24
CVE-2026-41044 Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia — Apache ActiveMQ CWE-20 7.2AI High AI 2026-04-24
CVE-2026-41043 Apache ActiveMQ, Apache ActiveMQ Web: ActiveMQ Web Console - XSS vulnerability when browsing queues — Apache ActiveMQ CWE-79 5.4AI Medium AI 2026-04-24
CVE-2026-40466 Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI — Apache ActiveMQ Broker CWE-20 8.8AI High AI 2026-04-24
CVE-2026-40542 Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to accept authentication without proper mutual authentication verification — Apache HttpClient CWE-304 9.1AI Critical AI 2026-04-22
CVE-2026-33557 Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication — Apache Kafka CWE-1285 9.1AI Critical AI 2026-04-20
CVE-2025-66335 Apache Doris MCP Server: MCP SQL inject — Apache Doris MCP Server CWE-89 9.8AI Critical AI 2026-04-20
CVE-2026-33558 Apache Kafka, Apache Kafka Clients: Information Exposure Through Network Client Log Output — Apache Kafka CWE-533 5.9AI Medium AI 2026-04-20
CVE-2026-40948 Apache Airflow Providers Keycloak: OAuth Login CSRF — Missing State Parameter in Keycloak Auth Manager — Apache Airflow Providers Keycloak CWE-352 7.3AI High AI 2026-04-18
CVE-2026-32690 Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1 — Apache Airflow CWE-668 7.5AI High AI 2026-04-18

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.