Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2174

Browse all 2174 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE IDTitleCVSSSeverityPublished
CVE-2026-62393 Apache Kylin: Improper authorization in job information retrieval — Apache KylinCWE-280--2026-07-14
CVE-2026-62392 Apache Kylin: OS Command Injection via Async Query API — Apache KylinCWE-78--2026-07-14
CVE-2026-62390 Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API — Apache KylinCWE-89--2026-07-14
CVE-2026-58319 Apache Doris: Improper Authentication in Frontend HTTP API — Apache DorisCWE-306--2026-07-14
CVE-2026-59084 Apache Tomcat: EncryptInterceptor requirements not clearly documented — Apache TomcatCWE-1059--2026-07-14
CVE-2026-59083 Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass — Apache TomcatCWE-177--2026-07-14
CVE-2026-59245 Apache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the global all-DAGs permission (access_control privilege escalation via resource_name() collision) — Apache Airflow FAB providerCWE-269--2026-07-13
CVE-2026-58065 Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification — Apache Airflow Git providerCWE-322--2026-07-13
CVE-2026-41041 Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended API endpoints. — Apache GravitinoCWE-177--2026-07-13
CVE-2026-49876 Apache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs — Apache GravitinoCWE-918--2026-07-13
CVE-2026-49844 Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson() — Apache Log4j APICWE-116--2026-07-10
CVE-2026-40454 Apache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server data — Apache IoTDB C++ clientCWE-125--2026-07-10
CVE-2026-40452 Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users — Apache IoTDBCWE-863--2026-07-10
CVE-2026-40009 Apache IoTDB: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor — Apache IoTDBCWE-269--2026-07-10
CVE-2026-40008 Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC — Apache IoTDBCWE-470--2026-07-10
CVE-2026-40007 Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError — Apache IoTDBCWE-674--2026-07-10
CVE-2026-40006 Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver — Apache IoTDBCWE-789--2026-07-10
CVE-2026-40005 Apache IoTDB: Path Traversal in Pipe File Transfer Receiver — Apache IoTDBCWE-22--2026-07-10
CVE-2026-28564 Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials — Apache IoTDBCWE-613--2026-07-10
CVE-2026-57111 Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-Origin — Apache Helix RESTCWE-1385--2026-07-09
CVE-2026-41042 Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter — Apache GravitinoCWE-20--2026-07-08
CVE-2026-33264 Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize() — Apache AirflowCWE-502--2026-07-07
CVE-2026-49487 Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs — Apache AirflowCWE-200--2026-07-07
CVE-2026-48828 Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key — Apache AirflowCWE-200--2026-07-07
CVE-2026-49296 Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagSources/{dag_id} — Apache AirflowCWE-639--2026-07-07
CVE-2026-48891 Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.target — Apache AirflowCWE-200--2026-07-07
CVE-2026-48892 Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic options — Apache AirflowCWE-200--2026-07-07
CVE-2026-43825 Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel — Apache OpenNLP :: Core :: ML :: LibSVMCWE-502--2026-07-06
CVE-2026-49297 Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator) — Apache Airflow Google providerCWE-22--2026-07-06
CVE-2026-46588 Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input — Apache CamelCWE-20--2026-07-06

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.