Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2026-30898 Apache Airflow: Bad example of BashOperator shell injection via dag_run.conf — Apache Airflow CWE-77 8.8AI High AI 2026-04-18
CVE-2026-30912 Apache Airflow: Exposing stack trace in case of constraint error — Apache Airflow CWE-668 7.5AI High AI 2026-04-18
CVE-2026-25917 Apache Airflow: API extra-links triggers XCom deserialization/class instantiation (Airflow 3.1.5) — Apache Airflow CWE-502 9.8AI Critical AI 2026-04-18
CVE-2026-32228 Apache Airflow: Users with asset materialization permisssions could trigger Dags they had no access to — Apache Airflow CWE-863 7.1AI High AI 2026-04-18
CVE-2026-31987 Apache Airflow: JWT token appearing in logs — Apache Airflow CWE-532 6.5AI Medium AI 2026-04-16
CVE-2026-25219 Apache Airflow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access — Apache Airflow CWE-200 6.5 - 2026-04-15
CVE-2026-30778 Apache SkyWalking: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. — Apache SkyWalking CWE-202 7.5 - 2026-04-15
CVE-2025-54550 Apache Airflow: RCE by race condition in example_xcom dag — Apache Airflow CWE-94 8.8 - 2026-04-15
CVE-2026-31923 Apache APISIX: Openid-connect `tls_verify` field is disabled by default — Apache APISIX CWE-319 7.5 - 2026-04-14
CVE-2026-33929 Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code — Apache PDFBox Examples CWE-22 7.5 - 2026-04-14
CVE-2026-31924 Apache APISIX: Plugin tencent-cloud-cls log export uses plaintext HTTP — Apache APISIX CWE-319 7.5 - 2026-04-14
CVE-2026-31908 Apache APISIX: forward auth plugin allows header injection — Apache APISIX CWE-75 8.2 - 2026-04-14
CVE-2026-33858 Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API — Apache Airflow CWE-502 9.8 - 2026-04-13
CVE-2025-66236 Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI — Apache Airflow CWE-532 9.6 - 2026-04-13
CVE-2026-34476 Apache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP Server — Apache SkyWalking MCP CWE-918 9.1 - 2026-04-13
CVE-2026-35337 Apache Storm Client: RCE through Unsafe Deserialization via Kerberos TGT Credential Handling — Apache Storm Client CWE-502 8.8 - 2026-04-13
CVE-2026-35565 Apache Storm UI: Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Storm UI — Apache Storm UI CWE-79 5.4 - 2026-04-13
CVE-2026-40023 Apache Log4cxx, Apache Log4cxx (Conan), Apache Log4cxx (Brew): Silent log event loss in XMLLayout due to unescaped XML 1.0 forbidden characters — Apache Log4cxx CWE-116 5.3 - 2026-04-10
CVE-2026-40021 Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters — Apache Log4net CWE-116 9.1 - 2026-04-10
CVE-2026-34481 Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout — Apache Log4j JSON Template Layout CWE-116 4.8 - 2026-04-10
CVE-2026-34480 Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters — Apache Log4j Core CWE-116 5.8AI Medium AI 2026-04-10
CVE-2026-34479 Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters — Apache Log4j 1 to Log4j 2 bridge CWE-116 6.5AI Medium AI 2026-04-10
CVE-2026-34478 Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibility — Apache Log4j Core CWE-684 8.2AI High AI 2026-04-10
CVE-2026-34477 Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass — Apache Log4j Core CWE-297 8.2AI High AI 2026-04-10
CVE-2026-39304 Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM — Apache ActiveMQ Client 7.5 - 2026-04-10
CVE-2026-34500 Apache Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled — Apache Tomcat 8.1AI High AI 2026-04-09
CVE-2026-34487 Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token — Apache Tomcat CWE-532 7.5AI High AI 2026-04-09
CVE-2026-34486 Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor — Apache Tomcat CWE-311 7.5AI High AI 2026-04-09
CVE-2026-34483 Apache Tomcat: Incomplete escaping of JSON access logs — Apache Tomcat CWE-116 9.8AI Critical AI 2026-04-09
CVE-2026-32990 Apache Tomcat: Fix for CVE-2025-66614 is incomplete — Apache Tomcat CWE-20 9.1AI Critical AI 2026-04-09

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.