Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2026-25604 Apache Airflow AWS Auth Manager - Host Header Injection Leading to SAML Authentication Bypass — Apache Airflow Providers Amazon CWE-346 9.8AI Critical AI 2026-03-09
CVE-2025-69219 Apache Airflow Providers Http: Unsafe Pickle Deserialization in apache-airflow-providers-http leading to RCE via HttpOperator — Apache Airflow Providers Http CWE-913 8.8AI High AI 2026-03-09
CVE-2026-24713 Apache IoTDB: JEXL Expression Injection Vulnerability — Apache IoTDB CWE-20 9.1AI Critical AI 2026-03-09
CVE-2026-24015 Apache IoTDB: Insecure Default Configuration Vulnerability — Apache IoTDB CWE-1327 9.1AI Critical AI 2026-03-09
CVE-2026-24308 Apache ZooKeeper: Sensitive information disclosure in client configuration handling — Apache ZooKeeper CWE-532 7.5 - 2026-03-07
CVE-2026-24281 Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager — Apache ZooKeeper CWE-350 7.4 - 2026-03-07
CVE-2026-27446 Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation — Apache Artemis CWE-306 9.3 Critical 2026-03-04
CVE-2025-66168 Apache ActiveMQ, Apache ActiveMQ All Module, Apache ActiveMQ MQTT Module: MQTT control packet remaining length field is not properly validated — Apache ActiveMQ CWE-190 5.4 Medium 2026-03-04
CVE-2025-59060 Apache Ranger: Hostname verification bypass in NiFiRegistryClient — Apache Ranger CWE-297 5.3AI Medium AI 2026-03-03
CVE-2025-59059 Apache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreator — Apache Ranger CWE-94 9.8AI Critical AI 2026-03-03
CVE-2026-23969 Apache Superset: Exposure of Sensitive Information via Incomplete ClickHouse Function Filtering — Apache Superset CWE-89 9.8 - 2026-02-24
CVE-2026-23980 Apache Superset: Improper Neutralization of Special Elements used in a SQL Command — Apache Superset CWE-89 8.8 - 2026-02-24
CVE-2026-23982 Apache Superset: Improper Authorization in Dataset Creation Allows Access Control Bypass — Apache Superset CWE-863 6.5 - 2026-02-24
CVE-2026-23983 Apache Superset: Sensitive Data Exposure via REST API (disabled by default) — Apache Superset CWE-200 6.5 - 2026-02-24
CVE-2026-23984 Apache Superset: SQLLab Read-Only Bypass on PostgreSQL — Apache Superset CWE-863 8.1 - 2026-02-24
CVE-2025-27555 Apache Airflow: Connection Secrets not masked in UI when Connection are added via Airflow cli — Apache Airflow CWE-532 6.5AI Medium AI 2026-02-24
CVE-2024-56373 Apache Airflow: SSTI to Code Execution in Airflow through Shared DB Information — Apache Airflow CWE-94 8.0AI High AI 2026-02-24
CVE-2026-25747 Apache Camel LevelDB: Deserialization of Untrusted Data in Camel LevelDB — Apache Camel LevelDB CWE-502 8.8AI High AI 2026-02-23
CVE-2026-23552 Apache Camel: Camel-Keycloak: Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy — Apache Camel CWE-346 5.3AI Medium AI 2026-02-23
CVE-2025-65995 Apache Airflow: Disclosure of secrets to UI via kwargs — Apache Airflow CWE-209 6.5AI Medium AI 2026-02-21
CVE-2026-24734 Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass — Apache Tomcat Native CWE-20 7.5AI High AI 2026-02-17
CVE-2026-24733 Apache Tomcat: Security constraint bypass with HTTP/0.9 — Apache Tomcat CWE-20 7.5AI High AI 2026-02-17
CVE-2025-66614 Apache Tomcat: Client certificate verification bypass due to virtual host mapping — Apache Tomcat CWE-20 9.8AI Critical AI 2026-02-17
CVE-2026-25087 Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering — Apache Arrow CWE-416 9.8AI Critical AI 2026-02-17
CVE-2026-25903 Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates — Apache NiFi CWE-862 6.5AI Medium AI 2026-02-17
CVE-2025-33042 Apache Avro Java SDK: Code injection on Java generated code — Apache Avro Java SDK CWE-94 9.8 - 2026-02-13
CVE-2026-24343 Apache HertzBeat: Uncontrolled Resource Consumption via Crafted XPath Expressions — Apache HertzBeat CWE-643 9.4AI Critical AI 2026-02-10
CVE-2026-23906 Apache Druid: Authentication Bypass via LDAP Anonymous Bind — Apache Druid CWE-287 9.8AI Critical AI 2026-02-10
CVE-2026-23901 Apache Shiro: Brute force attack possible to determine valid user names — Apache Shiro CWE-208 6.5 - 2026-02-10
CVE-2026-22922 Apache Airflow: Airflow externalLogUrl Permission Bypass — Apache Airflow CWE-648 4.3AI Medium AI 2026-02-09

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.