Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2025-49656 Apache Jena: Administrative users can create files outside the server directory space via the admin UI — Apache Jena CWE-22 4.9 - 2025-07-21
CVE-2025-48795 Apache CXF: Denial of Service and sensitive data exposure in logs — Apache CXF CWE-400 5.5 - 2025-07-15
CVE-2025-53689 Apache Jackrabbit: XXE vulnerability in jackrabbit-spi-commons — Apache Jackrabbit CWE-611 9.8 - 2025-07-14
CVE-2024-41169 Apache Zeppelin: raft directory listing and file read — Apache Zeppelin CWE-664 7.5AI High AI 2025-07-12
CVE-2025-48924 Apache Commons Lang, Apache Commons Lang: ClassUtils.getClass(...) can throw a StackOverflowError on very long inputs — Apache Commons Lang CWE-674 7.5AI High AI 2025-07-11
CVE-2025-53506 Apache Tomcat: DoS via excessive h2 streams at connection start — Apache Tomcat CWE-400 7.5 - 2025-07-10
CVE-2025-52520 Apache Tomcat: DoS via integer overflow in multipart file upload — Apache Tomcat CWE-190 7.5 - 2025-07-10
CVE-2025-52434 Apache Tomcat: APR/Native Connector crash leading to DoS — Apache Tomcat CWE-362 8.1 - 2025-07-10
CVE-2025-53020 Apache HTTP Server: HTTP/2 DoS by Memory Increase — Apache HTTP Server CWE-401 9.1 - 2025-07-10
CVE-2025-49812 Apache HTTP Server: mod_ssl TLS upgrade attack — Apache HTTP Server CWE-287 7.4AI High AI 2025-07-10
CVE-2025-49630 Apache HTTP Server: mod_proxy_http2 denial of service — Apache HTTP Server CWE-617 7.5AI High AI 2025-07-10
CVE-2025-23048 Apache HTTP Server: mod_ssl access control bypass with session resumption — Apache HTTP Server CWE-284 8.1AI High AI 2025-07-10
CVE-2024-43394 Apache HTTP Server: SSRF on Windows due to UNC paths — Apache HTTP Server CWE-918 7.5 - 2025-07-10
CVE-2024-47252 Apache HTTP Server: mod_ssl error log variable escaping — Apache HTTP Server CWE-150 5.3AI Medium AI 2025-07-10
CVE-2024-43204 Apache HTTP Server: SSRF with mod_headers setting Content-Type header — Apache HTTP Server CWE-918 5.9AI Medium AI 2025-07-10
CVE-2024-42516 Apache HTTP Server: HTTP response splitting — Apache HTTP Server CWE-20 5.3AI Medium AI 2025-07-10
CVE-2025-27446 Apache APISIX Java Plugin Runner: Local listening file permissions in APISIX plugin runner allow a local attacker to elevate privileges — Apache APISIX Java Plugin Runner CWE-732 7.8 - 2025-07-06
CVE-2024-35164 Apache Guacamole: Improper input validation of console codes — Apache Guacamole CWE-129 6.8 Medium 2025-07-02
CVE-2025-46647 Apache APISIX: improper validation of issuer from introspection discovery url in plugin openid-connect — Apache APISIX CWE-302 7.5AI High AI 2025-07-02
CVE-2025-32897 Apache Seata (incubating): Deserialization of untrusted Data in Apache Seata Server — Apache Seata (incubating) CWE-502 9.8AI Critical AI 2025-06-28
CVE-2025-50213 Apache Airflow Providers Snowflake: Potential SQL injection in CopyFromExternalStageToSnowflakeOperator — Apache Airflow Providers Snowflake CWE-75 9.8AI Critical AI 2025-06-24
CVE-2025-32896 Apache SeaTunnel: Unauthenticated insecure access — Apache SeaTunnel CWE-306 9.8AI Critical AI 2025-06-19
CVE-2025-31698 Apache Traffic Server: Client IP address from PROXY protocol is not used for ACL — Apache Traffic Server CWE-284 - - AI 2025-06-19
CVE-2025-49763 Apache Traffic Server: Remote DoS via memory exhaustion in ESI Plugin — Apache Traffic Server CWE-400 7.5AI High AI 2025-06-19
CVE-2025-48976 Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers — Apache Commons FileUpload 7.5 - 2025-06-16
CVE-2025-49124 Apache Tomcat: exe side-loading via icalcs.exe in Tomcat installer for Windows — Apache Tomcat CWE-426 7.8AI High AI 2025-06-16
CVE-2025-49125 Apache Tomcat: Security constraint bypass for pre/post-resources — Apache Tomcat CWE-288 9.1 - 2025-06-16
CVE-2025-48988 Apache Tomcat: FileUpload large number of parts with headers DoS — Apache Tomcat CWE-770 7.5 - 2025-06-16
CVE-2025-47869 Apache NuttX RTOS: examples/xmlrpc: Fix calls buffers size. — Apache NuttX RTOS CWE-119 9.8AI Critical AI 2025-06-16
CVE-2025-47868 Apache NuttX RTOS: tools/bdf-converter.: tools/bdf-converter: Fix loop termination condition. — Apache NuttX RTOS: tools/bdf-converter. CWE-787 9.8AI Critical AI 2025-06-16

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.