Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2345

Browse all 2345 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2026-65948 Apache Ranger: UnixAuth lacks brute-force protection — Apache Ranger CWE-307 - - 2026-08-10
CVE-2026-44630 Apache IoTDB: RPC service denial of service via unchecked Thrift string length — Apache IoTDB CWE-789 - - 2026-08-10
CVE-2026-71559 Apache Fory: Uncaught panic (remote DoS) in Go meta-string decoder from untrusted metadata — Apache Fory CWE-502 - - 2026-08-07
CVE-2026-71558 Apache Fory: Heap type confusion in C++ polymorphic smart-pointer deserialization — Apache Fory CWE-502 - - 2026-08-07
CVE-2026-71560 Apache Fory: Out-of-bounds heap read in C++ struct deserializer tagged-int fast-path — Apache Fory CWE-502 - - 2026-08-07
CVE-2025-49506 Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack — Apache Portable Runtime Utility CWE-208 - - 2026-08-06
CVE-2026-32327 Apache Portable Runtime Utility: apr-util XML stack recursion crash — Apache Portable Runtime Utility CWE-674 - - 2026-08-06
CVE-2026-34191 Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle — Apache Portable Runtime Utility CWE-89 - - 2026-08-06
CVE-2026-34501 Apache Portable Runtime Utility: Heap buffer overflow in APR redis client — Apache Portable Runtime Utility CWE-122 - - 2026-08-06
CVE-2026-34502 Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client — Apache Portable Runtime Utility CWE-122 - - 2026-08-06
CVE-2026-57818 Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider — Apache CXF CWE-367 - - 2026-08-06
CVE-2026-61466 Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation — Apache CXF CWE-304 - - 2026-08-06
CVE-2026-63687 Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters — Apache CXF CWE-345 - - 2026-08-06
CVE-2026-65583 Apache CXF: Self-issued ID token claims validation skipped — Apache CXF CWE-345 - - 2026-08-06
CVE-2026-68079 Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay — Apache CXF CWE-294 - - 2026-08-06
CVE-2026-68481 Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider — Apache CXF CWE-672 - - 2026-08-06
CVE-2026-65432 Apache CXF: XXE via WSDL/XSD import parsing — Apache CXF CWE-611 - - 2026-08-06
CVE-2026-57817 Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow — Apache CXF CWE-20 - - 2026-08-06
CVE-2026-66909 Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage — Apache CXF CWE-502 - - 2026-08-06
CVE-2026-64958 Apache CXF: Denial of service via message header attachments — Apache CXF CWE-400 - - 2026-08-06
CVE-2026-57819 Apache CXF: No default restriction on the amount of form parameters per message — Apache CXF CWE-400 - - 2026-08-06
CVE-2026-54225 Apache CXF: Denial of Service attack via large attachments — Apache CXF CWE-770 - - 2026-08-06
CVE-2026-64640 Apache Polaris: register endpoint reads attacker-controlled storage location before allowed-locations validation — Apache Polaris CWE-863 5.3 Medium 2026-08-06
CVE-2026-60053 Apache Answer: Residual Administrative API Key Access After Role or Account Revocation — Apache Answer CWE-613 - - 2026-08-05
CVE-2026-60023 Apache Answer: Unauthorized disclosure of deleted or pending answer content — Apache Answer CWE-200 - - 2026-08-05
CVE-2026-50749 Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions — Apache Answer CWE-863 - - 2026-08-05
CVE-2026-48912 Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL — Apache Answer CWE-639 - - 2026-08-05
CVE-2026-48911 Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow — Apache Answer CWE-306 - - 2026-08-05
CVE-2026-48834 Apache Answer: Denial of service via crafted Accept-Language header parsing — Apache Answer CWE-400 - - 2026-08-05
CVE-2026-61486 Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input — Apache Lucy CWE-121 - - 2026-08-05

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.