vendor

apache

180 thingsrelated by NVD

Its products

traffic server 31 http server 27 airflow 23 artemis 8 apache-airflow-providers-fab 7 qpid broker-j 6 cloudstack 5 neethi 5 nifi 5 sling xss protection api 5 zookeeper 5 impala 4 camel 3 dolphinscheduler 3 hive 3 nutch 3 wss4j 3 apache-airflow-providers-keycloak 2 doris mcp server 2 iotdb 2 nuttx 2 opennlp 2 tomcat 2 activemq 1 activemq all 1 activemq broker 1 apache-airflow-providers-akeyless 1 apache-airflow-providers-amazon 1 apache-airflow-providers-apache-kafka 1 apache-airflow-providers-apache-yandex 1 apache-airflow-providers-ftp 1 apache-airflow-providers-git 1 apache-airflow-providers-google 1 apr-util 1 atlas 1 freemarker 1 gravitino 1 httpclient 1 ignite 1 kyuubi 1

The 40 with the most things, of 47.

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

httpd: httpd: Denial of Service via integer overflow in mod_dav_fs
CVE-2026-93546
Severity high
Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64…
CVE-2026-92899
Severity medium
apache-qpid-broker-j: org.apache.qpid/qpid-broker-plugins-management-http: Apache Qpid Broker-J: Unauthorized management session access via…
CVE-2026-92609
Severity critical
Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to…
CVE-2026-92608
Severity high
Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message…
CVE-2026-92573
Severity medium
org.apache.qpid/qpid-broker-plugins-amqp-0-8-protocol: Apache Qpid Broker-J: Denial of Service via unbounded type nesting
CVE-2026-92564
Severity high
org.apache.qpid/qpid-broker-plugins-amqp-0-10-protocol: Apache Qpid Broker-J: Denial of Service via excessive memory allocation in AMQP…
CVE-2026-92560
Severity high
qpid-java: org.apache.qpid/qpid-broker-plugins-amqp-0-8-protocol: Apache Qpid Broker-J: Denial of Service via excessive memory allocation…
CVE-2026-92550
Severity high
Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. This issue…
CVE-2026-92001
Severity medium
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue…
CVE-2026-91999
Severity medium
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue…
CVE-2026-91928
Severity medium
When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes…
CVE-2026-91867
Severity medium
Neethi: Neethi: Denial of Service via crafted WS-Policy documents
CVE-2026-91866
Severity high
org.apache.neethi/neethi: Apache Neethi: Denial of Service via crafted WS-Policy documents
CVE-2026-91865
Severity high
org.apache.neethi/neethi: Apache Neethi: Denial of Service via crafted WS-Policy documents
CVE-2026-91864
Severity high
org.apache.neethi/neethi: Apache Neethi: Denial of Service via uncontrolled recursion in WS-Policy document parsing
CVE-2026-91863
Severity high
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue…
CVE-2026-91852
Severity medium
org.apache.wss4j/wss4j-ws-security-dom: Apache WSS4J: Authentication bypass via unsigned SAML sender-vouches assertion
CVE-2026-88920
Severity critical
Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and…
CVE-2026-87976
Severity high
Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field…
CVE-2026-86792
Severity high
Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting…
CVE-2026-86473
Severity critical
Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the…
CVE-2026-86466
Severity high
Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a…
CVE-2026-86465
Severity medium
Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing…
CVE-2026-86462
Severity critical
Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list…
CVE-2026-86089
Severity high
Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak…
CVE-2026-85532
Severity high
org.apache.freemarker/freemarker: Apache FreeMarker: Path traversal via malformed locale identifier
CVE-2026-84939
Severity critical
zookeeper: Apache ZooKeeper: Operational log forgery via newline injection
CVE-2026-84501
Severity medium
When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields into Apache…
CVE-2026-84439
Severity medium
The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL and…
CVE-2026-82617
Severity critical
Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow…
CVE-2026-82561
Severity medium
When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the…
CVE-2026-82355
Severity medium
Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented…
CVE-2026-82311
Severity critical
Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password…
CVE-2026-82310
Severity high
Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization…
CVE-2026-81866
Severity medium
Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource…
CVE-2026-80354
Severity high
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability in custom…
CVE-2026-80352
Severity critical
Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper…
CVE-2026-80351
Severity critical
The `deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authenticated client to…
CVE-2026-79993
Severity high
httpd: httpd: Information disclosure in mod_userdir via single-dot path equivalence
CVE-2026-79768
Severity medium
Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client…
CVE-2026-76187
Severity critical
Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token…
CVE-2026-76186
Severity critical
An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation…
CVE-2026-75880
Severity medium
Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags…
CVE-2026-75158
Severity medium
Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login…
CVE-2026-75156
Severity critical
Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An…
CVE-2026-74761
Severity high
httpd: httpd: Authentication state corruption via concurrent Digest authentication requests
CVE-2026-73637
Severity high
httpd: httpd: Authentication bypass via credential replay in mod_auth_digest
CVE-2026-73636
Severity high
org.apache.parquet/parquet-hadoop: Apache Parquet Hadoop: KMS token disclosure due to missing host validation
CVE-2026-73334
Severity high
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the…
CVE-2026-73192
Severity medium
org.apache.httpcomponents.client5/httpclient5: Apache HttpComponents Client: Server impersonation via improper TLS hostname verification
CVE-2026-71290
Severity critical
Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the…
CVE-2026-70469
Severity high
Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on…
CVE-2026-68971
Severity medium
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in…
CVE-2026-68970
Severity medium
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the…
CVE-2026-68969
Severity medium
Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed…
CVE-2026-68968
Severity high
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection…
CVE-2026-68872
Severity medium
The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the…
CVE-2026-68871
Severity medium
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections…
CVE-2026-68868
Severity medium
tomcat: Apache Tomcat: Improper Authentication due to principal lookup failure
CVE-2026-68569
Severity high
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard…
CVE-2026-68076
Severity medium
artemis-openwire-protocol: AMQ Broker Artemis: pre-authentication arbitrary durable queue deletion via OpenWire RemoveSubscriptionInfo
CVE-2026-67593
Severity critical
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by…
CVE-2026-67587
Severity high
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That…
CVE-2026-67260
Severity high
OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer Versions Affected: - 3.0.0-M4 -…
CVE-2026-67211
Severity high
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all…
CVE-2026-66256
Severity high
Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server…
CVE-2026-65324
Severity high
Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and…
CVE-2026-65181
Severity high
Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure…
CVE-2026-65100
Severity medium
Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has…
CVE-2026-65017
Severity medium
httpd: httpd: Denial of Service via charset conversion failure in mod_xml2enc
CVE-2026-63686
Severity high
httpd: httpd: Arbitrary code execution via oversized Host header in mod_vhost_alias
CVE-2026-63292
Severity high
httpd: httpd: unauthorized connection to arbitrary hosts via crafted FTP PASV response
CVE-2026-63045
Severity high
zookeeper: Apache ZooKeeper: Improper certificate validation in FIPS mode allows quorum compromise
CVE-2026-59969
Severity high
Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue…
CVE-2026-59797
Severity critical
zookeeper: Apache ZooKeeper: Information disclosure via SetWatches reconnect replay
CVE-2026-59739
Severity high
httpd: httpd: Denial of Service via out-of-bounds write during Windows path expansion
CVE-2026-59685
Severity high
In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced…
CVE-2026-59245
Severity high
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value…
CVE-2026-59244
Severity medium
The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a…
CVE-2026-59243
Severity critical
Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through…
CVE-2026-59242
Severity medium
httpd: httpd: Information disclosure via direct request to the WebDAV state directory
CVE-2026-58415
Severity medium
Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects…
CVE-2026-58189
Severity high
Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server…
CVE-2026-58188
Severity high
The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue…
CVE-2026-58187
Severity high
The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache…
CVE-2026-58186
Severity high
The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11…
CVE-2026-58185
Severity critical
The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This…
CVE-2026-58184
Severity high
The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server…
CVE-2026-58183
Severity high
The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache…
CVE-2026-58182
Severity high
The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache…
CVE-2026-58181
Severity high
The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache Traffic Server…
CVE-2026-58180
Severity high
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic…
CVE-2026-58179
Severity critical
The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects Apache Traffic…
CVE-2026-58178
Severity high
Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0.0 through…
CVE-2026-58175
Severity high
Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This issue affects Apache…
CVE-2026-58164
Severity high
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache…
CVE-2026-58163
Severity critical
The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache…
CVE-2026-58162
Severity critical
Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache…
CVE-2026-58161
Severity high
Apache Traffic Server reads out of bounds while parsing DNS answers. This issue affects Apache Traffic Server: from 8.0.0 through…
CVE-2026-58160
Severity medium

← Previous 1 of 2 Next →