| httpd: httpd: Denial of Service via integer overflow in mod_dav_fs CVE-2026-93546 | Severity high |
| Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64… CVE-2026-92899 | Severity medium |
| apache-qpid-broker-j: org.apache.qpid/qpid-broker-plugins-management-http: Apache Qpid Broker-J: Unauthorized management session access via… CVE-2026-92609 | Severity critical |
| Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to… CVE-2026-92608 | Severity high |
| Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message… CVE-2026-92573 | Severity medium |
| org.apache.qpid/qpid-broker-plugins-amqp-0-8-protocol: Apache Qpid Broker-J: Denial of Service via unbounded type nesting CVE-2026-92564 | Severity high |
| org.apache.qpid/qpid-broker-plugins-amqp-0-10-protocol: Apache Qpid Broker-J: Denial of Service via excessive memory allocation in AMQP… CVE-2026-92560 | Severity high |
| qpid-java: org.apache.qpid/qpid-broker-plugins-amqp-0-8-protocol: Apache Qpid Broker-J: Denial of Service via excessive memory allocation… CVE-2026-92550 | Severity high |
| Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS.
This issue… CVE-2026-92001 | Severity medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS.
This issue… CVE-2026-91999 | Severity medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS.
This issue… CVE-2026-91928 | Severity medium |
| When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes… CVE-2026-91867 | Severity medium |
| Neethi: Neethi: Denial of Service via crafted WS-Policy documents CVE-2026-91866 | Severity high |
| org.apache.neethi/neethi: Apache Neethi: Denial of Service via crafted WS-Policy documents CVE-2026-91865 | Severity high |
| org.apache.neethi/neethi: Apache Neethi: Denial of Service via crafted WS-Policy documents CVE-2026-91864 | Severity high |
| org.apache.neethi/neethi: Apache Neethi: Denial of Service via uncontrolled recursion in WS-Policy document parsing CVE-2026-91863 | Severity high |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS.
This issue… CVE-2026-91852 | Severity medium |
| org.apache.wss4j/wss4j-ws-security-dom: Apache WSS4J: Authentication bypass via unsigned SAML sender-vouches assertion CVE-2026-88920 | Severity critical |
| Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and… CVE-2026-87976 | Severity high |
| Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field… CVE-2026-86792 | Severity high |
| Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting… CVE-2026-86473 | Severity critical |
| Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the… CVE-2026-86466 | Severity high |
| Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a… CVE-2026-86465 | Severity medium |
| Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing… CVE-2026-86462 | Severity critical |
| Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list… CVE-2026-86089 | Severity high |
| Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak… CVE-2026-85532 | Severity high |
| org.apache.freemarker/freemarker: Apache FreeMarker: Path traversal via malformed locale identifier CVE-2026-84939 | Severity critical |
| zookeeper: Apache ZooKeeper: Operational log forgery via newline injection CVE-2026-84501 | Severity medium |
| When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields into Apache… CVE-2026-84439 | Severity medium |
| The two built-in name-finder patterns exposed by
opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL
and… CVE-2026-82617 | Severity critical |
| Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow… CVE-2026-82561 | Severity medium |
| When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the… CVE-2026-82355 | Severity medium |
| Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented… CVE-2026-82311 | Severity critical |
| Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password… CVE-2026-82310 | Severity high |
| Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization… CVE-2026-81866 | Severity medium |
| Authorization bypass through User-Controlled key vulnerability in Apache Camel K.
An authorization vulnerability in custom resource… CVE-2026-80354 | Severity high |
| Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K.
A YAML injection vulnerability in custom… CVE-2026-80352 | Severity critical |
| Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K.
An improper… CVE-2026-80351 | Severity critical |
| The `deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authenticated client to… CVE-2026-79993 | Severity high |
| httpd: httpd: Information disclosure in mod_userdir via single-dot path equivalence CVE-2026-79768 | Severity medium |
| Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client… CVE-2026-76187 | Severity critical |
| Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token… CVE-2026-76186 | Severity critical |
| An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation… CVE-2026-75880 | Severity medium |
| Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags… CVE-2026-75158 | Severity medium |
| Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login… CVE-2026-75156 | Severity critical |
| Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms.
An… CVE-2026-74761 | Severity high |
| httpd: httpd: Authentication state corruption via concurrent Digest authentication requests CVE-2026-73637 | Severity high |
| httpd: httpd: Authentication bypass via credential replay in mod_auth_digest CVE-2026-73636 | Severity high |
| org.apache.parquet/parquet-hadoop: Apache Parquet Hadoop: KMS token disclosure due to missing host validation CVE-2026-73334 | Severity high |
| An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the… CVE-2026-73192 | Severity medium |
| org.apache.httpcomponents.client5/httpclient5: Apache HttpComponents Client: Server impersonation via improper TLS hostname verification CVE-2026-71290 | Severity critical |
| Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the… CVE-2026-70469 | Severity high |
| Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on… CVE-2026-68971 | Severity medium |
| Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in… CVE-2026-68970 | Severity medium |
| Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the… CVE-2026-68969 | Severity medium |
| Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed… CVE-2026-68968 | Severity high |
| The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection… CVE-2026-68872 | Severity medium |
| The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the… CVE-2026-68871 | Severity medium |
| The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections… CVE-2026-68868 | Severity medium |
| tomcat: Apache Tomcat: Improper Authentication due to principal lookup failure CVE-2026-68569 | Severity high |
| Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard… CVE-2026-68076 | Severity medium |
| artemis-openwire-protocol: AMQ Broker Artemis: pre-authentication arbitrary durable queue deletion via OpenWire RemoveSubscriptionInfo CVE-2026-67593 | Severity critical |
| Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by… CVE-2026-67587 | Severity high |
| Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That… CVE-2026-67260 | Severity high |
| OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer
Versions Affected:
- 3.0.0-M4
-… CVE-2026-67211 | Severity high |
| ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig.
This issue affects Apache Shindig: all… CVE-2026-66256 | Severity high |
| Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server… CVE-2026-65324 | Severity high |
| Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and… CVE-2026-65181 | Severity high |
| Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure… CVE-2026-65100 | Severity medium |
| Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has… CVE-2026-65017 | Severity medium |
| httpd: httpd: Denial of Service via charset conversion failure in mod_xml2enc CVE-2026-63686 | Severity high |
| httpd: httpd: Arbitrary code execution via oversized Host header in mod_vhost_alias CVE-2026-63292 | Severity high |
| httpd: httpd: unauthorized connection to arbitrary hosts via crafted FTP PASV response CVE-2026-63045 | Severity high |
| zookeeper: Apache ZooKeeper: Improper certificate validation in FIPS mode allows quorum compromise CVE-2026-59969 | Severity high |
| Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.
This issue… CVE-2026-59797 | Severity critical |
| zookeeper: Apache ZooKeeper: Information disclosure via SetWatches reconnect replay CVE-2026-59739 | Severity high |
| httpd: httpd: Denial of Service via out-of-bounds write during Windows path expansion CVE-2026-59685 | Severity high |
| In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced… CVE-2026-59245 | Severity high |
| Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value… CVE-2026-59244 | Severity medium |
| The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a… CVE-2026-59243 | Severity critical |
| Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through… CVE-2026-59242 | Severity medium |
| httpd: httpd: Information disclosure via direct request to the WebDAV state directory CVE-2026-58415 | Severity medium |
| Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification.
This issue affects… CVE-2026-58189 | Severity high |
| Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors.
This issue affects Apache Traffic Server… CVE-2026-58188 | Severity high |
| The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service.
This issue… CVE-2026-58187 | Severity high |
| The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses.
This issue affects Apache… CVE-2026-58186 | Severity high |
| The Apache Traffic Server intercept plugin has a use-after-free.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11… CVE-2026-58185 | Severity critical |
| The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching.
This… CVE-2026-58184 | Severity high |
| The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input.
This issue affects Apache Traffic Server… CVE-2026-58183 | Severity high |
| The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state.
This issue affects Apache… CVE-2026-58182 | Severity high |
| The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input.
This issue affects Apache… CVE-2026-58181 | Severity high |
| The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input.
This issue affects Apache Traffic Server… CVE-2026-58180 | Severity high |
| The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input.
This issue affects Apache Traffic… CVE-2026-58179 | Severity critical |
| The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs.
This issue affects Apache Traffic… CVE-2026-58178 | Severity high |
| Apache Traffic Server leaks memory when handling HostDB SRV records.
This issue affects Apache Traffic Server: from 8.0.0 through… CVE-2026-58175 | Severity high |
| Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling.
This issue affects Apache… CVE-2026-58164 | Severity high |
| Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing.
This issue affects Apache… CVE-2026-58163 | Severity critical |
| The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI.
This issue affects Apache… CVE-2026-58162 | Severity critical |
| Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling.
This issue affects Apache… CVE-2026-58161 | Severity high |
| Apache Traffic Server reads out of bounds while parsing DNS answers.
This issue affects Apache Traffic Server: from 8.0.0 through… CVE-2026-58160 | Severity medium |