apache
451 known vulnerabilities affecting apache products.
Products
traffic_server 41
airflow 34
cxf 27
tomcat 26
thrift 23
cloudstack 20
http_server 15
camel 14
answer 12
ranger 11
wicket 11
inlong 10
activemq 10
fory 9
artemis 8
apache-airflow-providers-fab 8
syncope 8
activemq_broker 7
qpid_broker-j 7
qpid_proton-dotnet 6
qpid_proton-j 6
nifi 6
nimble 6
opennlp 6
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-57834 | Medium | 0.4% | 10.0 | Apache Traffic Server allows request smuggling if chunked messages are malformed… | |
| CVE-2026-49364 | Medium | 0.4% | 9.1 | An unauthenticated network-adjacent attacker can leverage discovery to capture c… | |
| CVE-2026-73334 | Medium | 0.4% | 8.1 | Potential problem for users of the org.apache.parquet.crypto.keytools package in… | |
| CVE-2026-33267 | Medium | 0.4% | 10.0 | Improper Input Validation vulnerability in Apache Traffic Server. This issue af… | |
| CVE-2026-48911 | Medium | 0.4% | 7.5 | Insufficient Verification of Data Authenticity vulnerability in Apache Answer. … | |
| CVE-2026-58150 | Medium | 0.4% | 10.0 | Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allo… | |
| CVE-2026-55814 | Medium | 0.4% | 7.5 | Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. User… | |
| CVE-2026-58179 | Medium | 0.4% | 8.1 | The Apache Traffic Server regex_remap plugin overflows the stack and integers fr… | |
| CVE-2026-32227 | Medium | 0.4% | 9.8 | SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects … | |
| CVE-2026-63046 | Medium | 0.4% | 8.8 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection… | |
| CVE-2026-58189 | Medium | 0.4% | 7.5 | Apache Traffic Server allows redirect-limit bypass when plugins reset the retry … | |
| CVE-2026-45813 | Medium | 0.4% | 8.8 | Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apa… | |
| CVE-2026-34191 | Medium | 0.3% | 9.1 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti… | |
| CVE-2026-58184 | Medium | 0.3% | 8.2 | The Apache Traffic Server header_rewrite plugin can crash or corrupt memory duri… | |
| CVE-2026-60053 | Medium | 0.3% | 9.1 | Insufficient Session Expiration vulnerability in Apache Answer. This issue affe… | |
| CVE-2026-65948 | Medium | 0.3% | 7.3 | UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0. Note:… | |
| CVE-2026-57818 | Medium | 0.3% | 8.1 | A race condition in JCacheCodeDataProvider allows an attacker to redeem a single… | |
| CVE-2026-49050 | Medium | 0.3% | 8.8 | General user can mint admin access tokens via /access-tokens This issue affec… | |
| CVE-2026-45811 | Medium | 0.3% | 7.5 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerabi… | |
| CVE-2026-50622 | Medium | 0.3% | 8.8 | Description: Missing Authorization in Apache Atlas. A missing authorization vuln… | |
| CVE-2026-59655 | Medium | 0.3% | 7.5 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac… | |
| CVE-2026-59780 | Medium | 0.3% | 7.5 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac… | |
| CVE-2026-61397 | Medium | 0.3% | 7.5 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac… | |
| CVE-2026-65942 | Medium | 0.3% | 7.5 | TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.… | |
| CVE-2026-66722 | Medium | 0.3% | 7.2 | Improper authorization for CRUD operations on Project Roles and Project Role per… | |
| CVE-2026-58177 | Medium | 0.3% | 8.1 | The Apache Traffic Server Cripts framework has out-of-bounds writes, path traver… | |
| CVE-2026-59654 | Medium | 0.3% | 7.5 | Missing Release of Resource after Effective Lifetime vulnerability in Apache Clo… | |
| CVE-2026-24033 | Medium | 0.3% | 7.2 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')… | |
| CVE-2026-59085 | Medium | 0.3% | 9.1 | Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook … | |
| CVE-2026-59799 | Medium | 0.3% | 8.8 | Improper Privilege Management vulnerability in Apache CloudStack's Two-factor au… | |
| CVE-2026-68980 | Medium | 0.3% | 9.1 | Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets … | |
| CVE-2026-58159 | Medium | 0.3% | 8.2 | Apache Traffic Server can bypass IP access controls on UDS listeners and through… | |
| CVE-2026-61398 | Medium | 0.3% | 9.1 | Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI … | |
| CVE-2026-41920 | Medium | 0.3% | 9.3 | Improper Access Control vulnerability in Apache Traffic Server. This issue affe… | |
| CVE-2026-50222 | Medium | 0.3% | 7.5 | Missing Authorization, Exposure of Sensitive Information to an Unauthorized Acto… | |
| CVE-2026-62440 | Medium | 0.3% | 9.1 | Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service … | |
| CVE-2026-56624 | Medium | 0.3% | 7.3 | Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA S… | |
| CVE-2026-50631 | Medium | 0.3% | 7.4 | A race condition in AbstractOAuthDataProvider allows concurrent requests using t… | |
| CVE-2026-48145 | Medium | 0.3% | 7.5 | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Th… | |
| CVE-2026-58157 | Medium | 0.3% | 8.7 | Apache Traffic Server can reuse server sessions and tunnels improperly, exposing… | |
| CVE-2026-80354 | Medium | 0.3% | 8.1 | Authorization bypass through User-Controlled key vulnerability in Apache Camel K… | |
| CVE-2026-53561 | Medium | 0.3% | 7.4 | An improper authentication vulnerability in HiveServer2 SAML bearer-token valida… | |
| CVE-2026-63687 | Medium | 0.3% | 9.1 | Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT in… | |
| CVE-2026-65583 | Medium | 0.3% | 9.1 | Apache CXF’s OIDC relying-party token validation could accept self-issued ID tok… | |
| CVE-2026-59969 | Medium | 0.3% | 7.5 | Apache ZooKeeper quorum TLS fails to enforce peer hostname verification in FIPS-… | |
| CVE-2026-48144 | Medium | 0.3% | 9.1 | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Th… | |
| CVE-2026-71290 | Medium | 0.2% | 9.1 | Improper TLS hostname verification vulnerability in Apache HttpComponents Client… | |
| CVE-2026-86466 | Medium | 0.2% | 8.1 | Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager do… | |
| CVE-2026-58162 | Medium | 0.2% | 10.0 | The Apache Traffic Server certifier plugin generates certificates based on attac… | |
| CVE-2026-59657 | Medium | 0.2% | 7.5 | Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack wi… |