Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1663

Browse all 1663 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2025-52435 Apache Mynewt NimBLE: Invalid error handling in pause encryption procedure in NimBLE controller — Apache Mynewt NimBLE 7.5 -2026-01-10
CVE-2025-53470 Apache Mynewt NimBLE: Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driver — Apache Mynewt NimBLECWE-125 6.5 -2026-01-10
CVE-2025-53477 Apache Mynewt NimBLE: NULL Pointer Dereference in NimBLE host HCI layer — Apache Mynewt NimBLECWE-476 7.5 -2026-01-10
CVE-2025-62235 Apache Mynewt NimBLE: Incorrect handling of SMP Security Request could lead to undesirable pairing — Apache Mynewt NimBLECWE-290 7.5 -2026-01-10
CVE-2025-68637 Apache Uniffle: Insecure SSL Configuration in Uniffle HTTP Client — Apache UniffleCWE-297 5.9 -2026-01-07
CVE-2025-68280 Apache SIS: XML External Entity (XXE) vulnerability — Apache SISCWE-611 5.3 -2026-01-05
CVE-2025-66518 Apache Kyuubi: Unauthorized directory access due to missing path normalization — Apache KyuubiCWE-27 8.1 -2026-01-05
CVE-2025-47411 Apache StreamPipes: Leverage of User ID for Privilege Escalation — Apache StreamPipesCWE-269 8.8 -2026-01-01
CVE-2025-48769 Apache NuttX RTOS: fs/vfs/fs_rename: use after free — Apache NuttX RTOSCWE-416 9.1 -2026-01-01
CVE-2025-48768 Apache NuttX RTOS: fs/inode: fs_inoderemove root inode removal — Apache NuttX RTOSCWE-763 9.1 -2026-01-01
CVE-2025-66524 Apache NiFi: Deserialization of Untrusted Data in GetAsanaObject Processor — Apache NiFiCWE-502 7.5AIHighAI2025-12-19
CVE-2025-68161 Apache Log4j Core: Missing TLS hostname verification in Socket appender — Apache Log4j CoreCWE-297 7.4AIHighAI2025-12-18
CVE-2025-67895 Apache Airflow Providers Edge3: Edge3 Worker RPC RCE on Airflow 2 — Apache Airflow Providers Edge3CWE-669 8.8AIHighAI2025-12-17
CVE-2025-66388 Apache Airflow: Secrets in rendered templates not redacted properly and exposed in the UI — Apache AirflowCWE-201 6.5 -2025-12-15
CVE-2025-53960 Apache StreamPark: Uses the user’s password as the secret key — Apache StreamParkCWE-1240 7.5AIHighAI2025-12-12
CVE-2025-54947 Apache StreamPark: Use hard-coded key vulnerability — Apache StreamParkCWE-321 9.8AICriticalAI2025-12-12
CVE-2025-54981 Apache StreamPark: Weak Encryption Algorithm in StreamPark — Apache StreamParkCWE-327 7.5AIHighAI2025-12-12
CVE-2025-26866 Apache HugeGraph-Server: RAFT and deserialization vulnerability — Apache HugeGraph-ServerCWE-502 8.8AIHighAI2025-12-12
CVE-2025-58137 Apache Fineract: IDOR via self-service API — Apache FineractCWE-639 7.5AIHighAI2025-12-12
CVE-2025-58130 Apache Fineract: Server Key not masked — Apache FineractCWE-522 9.1AICriticalAI2025-12-12
CVE-2025-23408 Apache Fineract: weak password policy — Apache FineractCWE-521 9.8AICriticalAI2025-12-12
CVE-2025-66675 Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS) - version ranges fixed — Apache StrutsCWE-459 7.5AIHighAI2025-12-10
CVE-2025-58098 Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... — Apache HTTP ServerCWE-201 8.1 -2025-12-05
CVE-2025-66200 Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo — Apache HTTP Server 8.3 -2025-12-05
CVE-2025-65082 Apache HTTP Server: CGI environment variable override — Apache HTTP ServerCWE-150 7.5 -2025-12-05
CVE-2025-59775 Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF — Apache HTTP ServerCWE-918 5.3 -2025-12-05
CVE-2025-55753 Apache HTTP Server: mod_md (ACME), unintended retry intervals — Apache HTTP ServerCWE-190--2025-12-05
CVE-2025-66516 Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected — Apache Tika coreCWE-611 8.4 High2025-12-04
CVE-2025-64775 Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS) — Apache StrutsCWE-459 7.5 -2025-12-01
CVE-2025-59789 Apache bRPC: Stack Exhaustion via Unbounded Recursion in JSON Parser — Apache bRPCCWE-674 7.5AIHighAI2025-12-01

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.