Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2345

Browse all 2345 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

Found 47 results / 2345 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-70469 Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests — Apache NiFi CWE-409 - - 2026-09-16
CVE-2026-81866 Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration — Apache NiFi CWE-862 0.5 Low 2026-09-16
CVE-2026-82561 Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods — Apache NiFi CWE-862 5.9 Medium 2026-09-16
CVE-2026-86089 Apache NiFi: Missing Process Group Authorization for Connector Migration — Apache NiFi CWE-862 2.3 Low 2026-09-16
CVE-2026-68981 Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests — Apache NiFi CWE-409 8.8 High 2026-08-03
CVE-2026-68980 Apache NiFi: Authorization Bypass for Parameter Context Asset Deletion — Apache NiFi CWE-863 2.3 Low 2026-08-03
CVE-2026-62354 Apache NiFi: Incorrect Authorization for Parameter Context Validation Requests — Apache NiFi CWE-863 7.7 High 2026-08-03
CVE-2026-68979 Apache NiFi: Missing Authorization for Components Referenced by Parameter Context Updates — Apache NiFi CWE-862 5.9 Medium 2026-08-03
CVE-2026-44914 Apache NiFi: Missing Authorization of Restricted Permissions when Replacing Flow Contents — Apache NiFi CWE-862 - - 2026-06-22
CVE-2026-44911 Apache NiFi: Incorrect Authorization for Configuration Verification Requests — Apache NiFi CWE-863 - - 2026-06-22
CVE-2026-44913 Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL — Apache NiFi CWE-116 - - 2026-06-22
CVE-2026-54665 Apache NiFi: Missing Validation for Proxy Host Headers — Apache NiFi CWE-346 - - 2026-06-22
CVE-2026-39816 Apache NiFi: Missing Execute Code Required Permission on TinkerpopClientService — Apache NiFi CWE-862 8.8AI High AI 2026-05-08
CVE-2026-25903 Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates — Apache NiFi CWE-862 6.5AI Medium AI 2026-02-17
CVE-2025-66524 Apache NiFi: Deserialization of Untrusted Data in GetAsanaObject Processor — Apache NiFi CWE-502 7.5AI High AI 2025-12-19
CVE-2025-27017 Apache NiFi: Potential Insertion of MongoDB Password in Provenance Record — Apache NiFi CWE-538 6.5 - 2025-03-12
CVE-2024-56512 Apache NiFi: Missing Complete Authorization for Parameter and Service References — Apache NiFi CWE-638 6.5 - 2024-12-28
CVE-2024-52067 Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log — Apache NiFi CWE-532 4.9AI Medium AI 2024-11-21
CVE-2024-45477 Apache NiFi: Improper Neutralization of Input in Parameter Description — Apache NiFi CWE-79 4.6 Medium 2024-10-29
CVE-2024-37389 Apache NiFi: Improper Neutralization of Input in Parameter Context Description — Apache NiFi CWE-79 4.6 Medium 2024-07-08
CVE-2023-49145 Apache NiFi: Improper Neutralization of Input in Advanced User Interface for Jolt — Apache NiFi CWE-79 7.9 High 2023-11-27
CVE-2023-40037 Apache NiFi: Incomplete Validation of JDBC and JNDI Connection URLs — Apache NiFi CWE-184 8.1 - 2023-08-18
CVE-2023-36542 Apache NiFi: Potential Code Injection with Properties Referencing Remote Resources — Apache NiFi CWE-94 8.8 - 2023-07-29
CVE-2023-34212 Apache NiFi: Potential Deserialization of Untrusted Data with JNDI in JMS Components — Apache NiFi CWE-502 8.8 - 2023-06-12
CVE-2023-34468 Apache NiFi: Potential Code Injection with Database Services using H2 — Apache NiFi CWE-94 8.8 - 2023-06-12
CVE-2023-22832 Apache NiFi: Improper Restriction of XML External Entity References in ExtractCCDAAttributes — Apache NiFi CWE-611 7.5 - 2023-02-10
CVE-2022-33140 Improper Neutralization of Command Elements in Shell User Group Provider — Apache NiFi CWE-78 8.8 - 2022-06-15
CVE-2022-29265 Improper Restriction of XML External Entity References in Multiple Components — Apache NiFi CWE-611 7.5 - 2022-04-30
CVE-2022-26850 Insufficiently protected credentials — Apache NiFi 4.3 - 2022-04-06
CVE-2021-44145 Apache NiFi information disclosure by XXE — Apache NiFi 6.5 - 2021-12-17

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.