Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2345

Browse all 2345 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2026-68569 Apache Tomcat: Principal lookup can fail open in some cases — Apache Tomcat CWE-287 - - 2026-08-25
CVE-2026-68525 Apache Tomcat: Redirect after FORM auth may bypass method specific constraints — Apache Tomcat CWE-863 - - 2026-08-25
CVE-2026-66422 Apache Tomcat: Servlet role references can bypass declarative role constraints — Apache Tomcat CWE-285 - - 2026-08-25
CVE-2026-65927 Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control — Apache Tomcat CWE-193 - - 2026-08-25
CVE-2026-65905 Apache Tomcat: Limited replay attack possible with DIGEST authentication — Apache Tomcat CWE-294 - - 2026-08-25
CVE-2026-65637 Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete — Apache Tomcat CWE-20 - - 2026-08-25
CVE-2026-65183 Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets — Apache Tomcat CWE-367 - - 2026-08-25
CVE-2026-65182 Apache Tomcat: Bypass longest prefix security constraint — Apache Tomcat CWE-284 - - 2026-08-25
CVE-2026-49845 Apache Hive: SQL Injection vulnerability in HiveMetaStore partition-name direct-SQL paths — Apache Hive CWE-94 - - 2026-08-25
CVE-2026-55976 Apache Hive: SSRF vulnerability in Hive Avro Serde due to Insufficient input validation on avro.schema.url — Apache Hive CWE-918 - - 2026-08-25
CVE-2026-53561 Apache Hive: Unauthenticated authentication bypass in HiveServer2 HTTP SAML bearer-token validation allows impersonation of any Hive user — Apache Hive CWE-287 - - 2026-08-25
CVE-2026-49050 Apache DolphinScheduler: General user can mint admin access tokens via /access-tokens — Apache DolphinScheduler CWE-863 - - 2026-08-25
CVE-2026-75099 Apache Allura: Unauthenticated REST disclosure — Apache Allura CWE-200 - - 2026-08-24
CVE-2026-78329 Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes — Apache Camel CWE-20 - - 2026-08-24
CVE-2026-71300 Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection — Apache Camel CWE-20 - - 2026-08-24
CVE-2026-63621 Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy — Apache Camel CWE-20 - - 2026-08-24
CVE-2026-66908 Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted — Apache Camel CWE-287 - - 2026-08-24
CVE-2026-66907 Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result — Apache Camel CWE-23 - - 2026-08-24
CVE-2026-66906 Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir — Apache Camel CWE-23 - - 2026-08-24
CVE-2026-60093 Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir — Apache Camel CWE-23 - - 2026-08-24
CVE-2026-59230 Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled — Apache Camel CWE-20 - - 2026-08-24
CVE-2026-59654 Apache CloudStack: DoS caused by database connections leak — Apache CloudStack CWE-772 6.8 Medium 2026-08-21
CVE-2026-63046 Apache InLong: Agent Installer — Command Injection to RCE via Default Credentials — Apache InLong CWE-88 - - 2026-08-21
CVE-2026-47359 Apache CloudStack: OS Command Injection due to unsanitized mount command — Apache CloudStack CWE-78 - - 2026-08-21
CVE-2026-50112 Apache CloudStack: RCE and SSRF in direct download, metalink and NFS templates — Apache CloudStack CWE-78 - - 2026-08-21
CVE-2026-50222 Apache CloudStack: Improper access control in Userdata reference APIs — Apache CloudStack CWE-862 - - 2026-08-21
CVE-2026-59085 Apache CloudStack: Server-Side Request Forgery (SSRF) vulnerability in webhook module — Apache CloudStack CWE-918 - - 2026-08-21
CVE-2026-59655 Apache CloudStack: Unauthenticated OAuth provider client-secret disclosure — Apache CloudStack CWE-200 - - 2026-08-21
CVE-2026-59657 Apache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJob — Apache CloudStack CWE-312 - - 2026-08-21
CVE-2026-59780 Apache CloudStack: LDAP provider configuration disclosure — Apache CloudStack CWE-200 - - 2026-08-21

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.