Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2345

Browse all 2345 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

Found 25 results / 2345 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-44630 Apache IoTDB: RPC service denial of service via unchecked Thrift string length — Apache IoTDB CWE-789 - - 2026-08-10
CVE-2026-40452 Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users — Apache IoTDB CWE-863 - - 2026-07-10
CVE-2026-40009 Apache IoTDB: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor — Apache IoTDB CWE-269 - - 2026-07-10
CVE-2026-40008 Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC — Apache IoTDB CWE-470 - - 2026-07-10
CVE-2026-40007 Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError — Apache IoTDB CWE-674 - - 2026-07-10
CVE-2026-40006 Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver — Apache IoTDB CWE-789 - - 2026-07-10
CVE-2026-40005 Apache IoTDB: Path Traversal in Pipe File Transfer Receiver — Apache IoTDB CWE-22 - - 2026-07-10
CVE-2026-28564 Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials — Apache IoTDB CWE-613 - - 2026-07-10
CVE-2026-24013 Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC — Apache IoTDB CWE-290 - - 2026-07-06
CVE-2026-24012 Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query — Apache IoTDB CWE-400 - - 2026-07-06
CVE-2026-24014 Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write — Apache IoTDB CWE-284 - - 2026-07-06
CVE-2025-64152 Apache IoTDB: Path Traversal Vulnerability — Apache IoTDB CWE-22 - - 2026-06-26
CVE-2025-55017 Apache IoTDB: Path Traversal Vulnerability — Apache IoTDB CWE-22 - - 2026-06-26
CVE-2026-24713 Apache IoTDB: JEXL Expression Injection Vulnerability — Apache IoTDB CWE-20 9.1AI Critical AI 2026-03-09
CVE-2026-24015 Apache IoTDB: Insecure Default Configuration Vulnerability — Apache IoTDB CWE-1327 9.1AI Critical AI 2026-03-09
CVE-2025-48392 Apache IoTDB: DoS Vulnerability — Apache IoTDB 9.8AI Critical AI 2025-09-24
CVE-2025-48459 Apache IoTDB: Deserialization of untrusted Data — Apache IoTDB CWE-502 9.8AI Critical AI 2025-09-24
CVE-2025-26864 Apache IoTDB: Exposure of Sensitive Information in IoTDB OpenID Authentication — Apache IoTDB CWE-200 7.5AI High AI 2025-05-14
CVE-2024-24780 Apache IoTDB: Remote Code Execution with untrusted URI of User-defined function — Apache IoTDB 8.8AI High AI 2025-05-14
CVE-2023-46226 Apache IoTDB: Remote Code Execution (RCE) risk via the UDF — Apache IoTDB 9.8 - 2024-01-15
CVE-2023-51656 Apache IoTDB: Unsafe deserialize map in Sync Tool — Apache IoTDB CWE-502 9.8AI Critical AI 2023-12-21
CVE-2023-24831 Apache IoTDB grafana-connector Login Bypass Vulnerability — Apache IoTDB CWE-287 8.8 - 2023-04-17
CVE-2022-43766 Apache IoTDB prior to 0.13.3 allows DoS — Apache IoTDB 7.5 - 2022-10-26
CVE-2022-38370 No authorization of DatabaseConnectController in grafana-connector. — Apache IoTDB 5.3 - 2022-09-05
CVE-2022-38369 Login check vulnerability by session Id — Apache IoTDB 8.1 - 2022-09-05

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.