Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2345

Browse all 2345 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2026-77181 Apache Syncope: ClientApp update entitlement not effective — Apache Syncope CWE-863 - - 2026-09-14
CVE-2026-77883 Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist — Apache Syncope CWE-202 - - 2026-09-14
CVE-2026-78318 Apache Syncope: Unauthenticated reflected XSS in Console and Enduser — Apache Syncope CWE-79 - - 2026-09-14
CVE-2026-78330 Apache Syncope: Privilege escalation for admin user via JWT authentication — Apache Syncope CWE-266 - - 2026-09-14
CVE-2026-78336 Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user — Apache Syncope CWE-201 - - 2026-09-14
CVE-2026-82232 Apache Syncope: SQL injection via sort parameter in Task search — Apache Syncope CWE-89 - - 2026-09-14
CVE-2026-86460 Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence — Apache Syncope CWE-89 - - 2026-09-14
CVE-2026-87779 Apache Syncope: AES Secret Key disclosure via log output — Apache Syncope CWE-532 - - 2026-09-14
CVE-2026-87785 Apache Syncope: JWT subject spoofing — Apache Syncope CWE-290 - - 2026-09-14
CVE-2026-87802 Apache Syncope: SRA OAuth2 JWT signature verification bypass — Apache Syncope CWE-347 - - 2026-09-14
CVE-2026-68570 Apache Doris: Authorization bypass leading to unauthorized data access — Apache Doris CWE-863 - - 2026-09-14
CVE-2026-72524 Apache Doris: Authorization bypass allowing a low-privilege user to read/write/drop arbitrary tables — Apache Doris CWE-863 - - 2026-09-14
CVE-2026-82617 Apache OpenNLP, Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory built-in EMAIL and URL patterns — Apache OpenNLP 10.0 Critical 2026-09-11
CVE-2026-67211 Apache OpenNLP: OOM DoS via Unbounded Array Allocation in SymSpellModelSerializer — Apache OpenNLP CWE-789 - - 2026-09-11
CVE-2026-80354 Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace — Apache Camel K CWE-639 - - 2026-09-10
CVE-2026-80351 Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod — Apache Camel K CWE-95 - - 2026-09-10
CVE-2026-80352 Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects — Apache Camel K CWE-94 - - 2026-09-10
CVE-2026-84939 Apache FreeMarker, Apache FreeMarker: A malformed locale may be exploitable for path traversal attacks — Apache FreeMarker CWE-23 - - 2026-09-10
CVE-2026-49362 Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler Allows Unauthorized Queue Creation — Apache Artemis CWE-306 - - 2026-09-10
CVE-2026-49363 Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE Protocol Topology Subscription — Apache Artemis CWE-306 - - 2026-09-10
CVE-2026-49364 Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-Authentication Cluster Credential Exposure to Discovered Peers — Apache Artemis CWE-306 - - 2026-09-10
CVE-2026-57822 Apache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserialization may lead to denial of service — Apache Artemis - - 2026-09-10
CVE-2026-57967 Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session reattachment — Apache Artemis CWE-306 - - 2026-09-10
CVE-2026-67593 Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-authentication Openwire protocol handling can result in queue deletion — Apache Artemis CWE-306 - - 2026-09-10
CVE-2026-75880 Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to denial of service — Apache Artemis CWE-1333 - - 2026-09-10
CVE-2026-74761 Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId — Apache ActiveMQ Broker CWE-20 - - 2026-09-09
CVE-2026-73334 Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that skips host validation — Apache Parquet Hadoop CWE-20 - - 2026-09-09
CVE-2026-41871 Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API) — Apache Nutch CWE-862 - - 2026-09-09
CVE-2026-41869 Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch REST API) — Apache Nutch CWE-862 - - 2026-09-09
CVE-2026-41870 Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API) — Apache Nutch CWE-862 - - 2026-09-09

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.