Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2345

Browse all 2345 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

Found 24 results / 2345 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-60053 Apache Answer: Residual Administrative API Key Access After Role or Account Revocation — Apache Answer CWE-613 - - 2026-08-05
CVE-2026-60023 Apache Answer: Unauthorized disclosure of deleted or pending answer content — Apache Answer CWE-200 - - 2026-08-05
CVE-2026-50749 Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions — Apache Answer CWE-863 - - 2026-08-05
CVE-2026-48912 Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL — Apache Answer CWE-639 - - 2026-08-05
CVE-2026-48911 Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow — Apache Answer CWE-306 - - 2026-08-05
CVE-2026-48834 Apache Answer: Denial of service via crafted Accept-Language header parsing — Apache Answer CWE-400 - - 2026-08-05
CVE-2026-25700 Apache Answer: AdminToken not invalidated after admin deactivation — Apache Answer CWE-1259 - - 2026-06-10
CVE-2026-34905 Apache Answer: Unlisted Questions Accessible via Direct API Access — Apache Answer CWE-200 - - 2026-06-09
CVE-2026-34033 Apache Answer: HTML Content Injection in Email — Apache Answer CWE-80 - - 2026-06-09
CVE-2026-34031 Apache Answer: The custom avatar was not properly validated — Apache Answer CWE-434 - - 2026-06-09
CVE-2026-33582 Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory error — Apache Answer CWE-434 - - 2026-06-09
CVE-2026-25699 Apache Answer: Authorization Bypass in Timeline API — Apache Answer CWE-359 - - 2026-06-09
CVE-2026-25688 Apache Answer: XSS in AI Answer Rendering — Apache Answer CWE-87 - - 2026-06-09
CVE-2026-24735 Apache Answer: Revision API Improper Access Control leads to Information Disclosure — Apache Answer CWE-359 5.3AI Medium AI 2026-02-04
CVE-2025-29868 Apache Answer: Using externally referenced images can leak user privacy. — Apache Answer CWE-495 6.5 - 2025-04-01
CVE-2024-45719 Apache Answer: Predictable Authorization Token Using UUIDv1 — Apache Answer CWE-326 7.5 - 2024-11-22
CVE-2024-40761 Apache Answer: Avatar URL leaked user email addresses — Apache Answer CWE-326 7.5AI High AI 2024-09-25
CVE-2024-41888 Apache Answer: The link for resetting user password is not Single-Use — Apache Answer CWE-772 7.5AI High AI 2024-08-09
CVE-2024-41890 Apache Answer: The link to reset the user's password will remain valid after sending a new link — Apache Answer CWE-772 7.5AI High AI 2024-08-09
CVE-2024-29217 Apache Answer: XSS vulnerability when changing personal website — Apache Answer CWE-79 5.4 - 2024-04-21
CVE-2024-22393 Apache Answer: Pixel Flood Attack by uploading the large pixel file — Apache Answer CWE-434 6.5 - 2024-02-22
CVE-2024-23349 Apache Answer: XSS vulnerability when submitting summary — Apache Answer CWE-79 5.4 - 2024-02-22
CVE-2024-26578 Apache Answer: Repeated submission at registration created duplicate users with the same name — Apache Answer CWE-362 7.4 - 2024-02-22
CVE-2023-49619 Apache Answer: Repeated submissions using scripts resulted in an abnormal number of collections for questions. — Apache Answer CWE-362 - - AI 2024-01-10

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.