Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2345

Browse all 2345 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

Found 45 results / 2345 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-57818 Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider — Apache CXF CWE-367 - - 2026-08-06
CVE-2026-61466 Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation — Apache CXF CWE-304 - - 2026-08-06
CVE-2026-63687 Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters — Apache CXF CWE-345 - - 2026-08-06
CVE-2026-65583 Apache CXF: Self-issued ID token claims validation skipped — Apache CXF CWE-345 - - 2026-08-06
CVE-2026-68079 Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay — Apache CXF CWE-294 - - 2026-08-06
CVE-2026-68481 Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider — Apache CXF CWE-672 - - 2026-08-06
CVE-2026-65432 Apache CXF: XXE via WSDL/XSD import parsing — Apache CXF CWE-611 - - 2026-08-06
CVE-2026-57817 Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow — Apache CXF CWE-20 - - 2026-08-06
CVE-2026-66909 Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage — Apache CXF CWE-502 - - 2026-08-06
CVE-2026-64958 Apache CXF: Denial of service via message header attachments — Apache CXF CWE-400 - - 2026-08-06
CVE-2026-57819 Apache CXF: No default restriction on the amount of form parameters per message — Apache CXF CWE-400 - - 2026-08-06
CVE-2026-54225 Apache CXF: Denial of Service attack via large attachments — Apache CXF CWE-770 - - 2026-08-06
CVE-2026-50645 Apache CXF: No restriction on attachment headers per message — Apache CXF CWE-400 - - 2026-06-12
CVE-2026-50634 Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry — Apache CXF CWE-347 - - 2026-06-12
CVE-2026-50633 Apache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl — Apache CXF CWE-20 - - 2026-06-12
CVE-2026-50632 Apache CXF: JNDI Injection Vulnerability in JMSConfigFactory — Apache CXF CWE-20 - - 2026-06-12
CVE-2026-50631 Apache CXF: OAuth2: TOCTOU Race Condition in Refresh Token Processing — Apache CXF CWE-367 - - 2026-06-12
CVE-2026-50630 Apache CXF: OAuth2: HTTP Response Splitting via WWW-Authenticate Realm Injection — Apache CXF CWE-113 - - 2026-06-12
CVE-2026-50629 Apache CXF: OAuth2: Log Injection via Unsanitized Client Identifier — Apache CXF CWE-93 - - 2026-06-12
CVE-2026-50628 Apache CXF: OAuth2: Inverted IP Binding Check Defeats Security Control — Apache CXF CWE-20 - - 2026-06-12
CVE-2026-50627 Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator — Apache CXF CWE-289 - - 2026-06-12
CVE-2026-49875 Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointReferenceUtils — Apache CXF CWE-611 - - 2026-06-12
CVE-2026-50623 Apache CXF: Authentication Bypass in OAuth2 TokenIntrospectionService — Apache CXF CWE-287 - - 2026-06-12
CVE-2026-44417 Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE) — Apache CXF CWE-20 - - 2026-05-22
CVE-2026-44618 Apache CXF: XXE vulnerability in WS-Transfer functionality — Apache CXF CWE-611 - - 2026-05-22
CVE-2026-44930 Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository — Apache CXF CWE-90 - - 2026-05-22
CVE-2025-48913 Apache CXF: Untrusted JMS configuration can lead to RCE — Apache CXF CWE-20 9.8 - 2025-08-08
CVE-2025-48795 Apache CXF: Denial of Service and sensitive data exposure in logs — Apache CXF CWE-400 5.5 - 2025-07-15
CVE-2025-23184 Apache CXF: Denial of Service vulnerability with temporary files — Apache CXF CWE-400 5.9 Medium 2025-01-21
CVE-2024-41172 Apache CXF: Unrestricted memory consumption in CXF HTTP clients — Apache CXF CWE-401 7.5 - 2024-07-19

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.