apache
451 known vulnerabilities affecting apache products.
Products
traffic_server 41
airflow 34
cxf 27
tomcat 26
thrift 23
cloudstack 20
http_server 15
camel 14
answer 12
ranger 11
wicket 11
inlong 10
activemq 10
fory 9
artemis 8
apache-airflow-providers-fab 8
syncope 8
activemq_broker 7
qpid_broker-j 7
qpid_proton-dotnet 6
qpid_proton-j 6
nifi 6
nimble 6
opennlp 6
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-45426 | Low | 0.4% | 3.1 | Exploitation requires the attacker to already be an authenticated Airflow worker… | |
| CVE-2026-68969 | Low | 0.4% | 6.5 | Apache Airflow wrote Variable values and Connection `extra` contents to the audi… | |
| CVE-2026-50623 | Low | 0.4% | 4.8 | An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionSe… | |
| CVE-2026-66390 | Low | 0.4% | 6.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti… | |
| CVE-2026-75099 | Low | 0.4% | 5.3 | Unauthenticated REST disclosure of certain content items in Apache Allura. Th… | |
| CVE-2026-23903 | Low | 0.4% | 5.3 | Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This iss… | |
| CVE-2026-63621 | Low | 0.4% | 5.3 | Improper Input Validation, Improper Neutralization of Special Elements in Output… | |
| CVE-2026-65100 | Low | 0.4% | 4.8 | Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming t… | |
| CVE-2026-48589 | Low | 0.4% | 5.4 | Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases t… | |
| CVE-2026-41017 | Low | 0.4% | 5.9 | Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Sec… | |
| CVE-2026-42358 | Low | 0.3% | 6.5 | A bug in Apache Airflow's Variable response masker caused nested-key redaction (… | |
| CVE-2026-42360 | Low | 0.3% | 6.5 | A bug in Apache Airflow's rendered-template field handling caused nested sensiti… | |
| CVE-2026-46605 | Low | 0.3% | 4.3 | Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5… | |
| CVE-2026-48910 | Low | 0.3% | 6.5 | A carefully crafted editing request could trigger an XSS vulnerability on Apach… | |
| CVE-2026-58152 | Low | 0.3% | 5.9 | Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, co… | |
| CVE-2026-58158 | Low | 0.3% | 5.9 | Apache Traffic Server mishandles PROXY protocol input, truncating ports and over… | |
| CVE-2026-58187 | Low | 0.3% | 3.7 | The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on… | |
| CVE-2026-73239 | Low | 0.3% | 6.5 | Insecure Direct Object Reference (IDOR) due to missing permission checks for mul… | |
| CVE-2026-68076 | Low | 0.3% | 5.4 | Apache Airflow's environment-variable secrets backend resolved a team-scoped Con… | |
| CVE-2026-58185 | Low | 0.3% | 5.9 | The Apache Traffic Server intercept plugin has a use-after-free. This issue aff… | |
| CVE-2026-34033 | Low | 0.3% | 5.4 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vu… | |
| CVE-2025-59060 | Low | 0.3% | 5.3 | Hostname verification bypass issue in Apache Ranger NiFiRegistryClient is report… | |
| CVE-2026-68871 | Low | 0.3% | 6.5 | The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved … | |
| CVE-2026-68872 | Low | 0.3% | 6.5 | The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache A… | |
| CVE-2026-68971 | Low | 0.3% | 6.5 | Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}… | |
| CVE-2026-34905 | Low | 0.3% | 6.5 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac… | |
| CVE-2026-49326 | Low | 0.3% | 6.5 | Missing Authorization vulnerability in Apache HBase thrift and rest delegation s… | |
| CVE-2026-62354 | Low | 0.3% | 4.3 | Authorization handling for Parameter Context validation requests in Apache NiFi … | |
| CVE-2026-48912 | Low | 0.3% | 6.5 | Improper Input Validation vulnerability in Apache Answer. This issue affects Ap… | |
| CVE-2026-50749 | Low | 0.3% | 6.5 | Improper Authorization vulnerability in Apache Answer. This issue affects Apach… | |
| CVE-2026-44618 | Low | 0.3% | 5.3 | Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow a… | |
| CVE-2026-58301 | Low | 0.3% | 6.5 | When Apache Shiro is used with the Jakarta EE integration module, a low-privileg… | |
| CVE-2026-41115 | Low | 0.3% | 4.3 | An improper authorization vulnerability has been identified in Apache Kafka. Th… | |
| CVE-2026-61399 | Low | 0.3% | 4.8 | Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI … | |
| CVE-2026-43828 | Low | 0.3% | 6.5 | Default configurations of Apache Shiro send sensitive cookies in HTTPS session w… | |
| CVE-2026-66721 | Low | 0.3% | 2.7 | Missing authorization issue for domain admins in CloudStack's host tags listing … | |
| CVE-2026-50634 | Low | 0.3% | 6.5 | A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited t… | |
| CVE-2026-66797 | Low | 0.3% | 5.4 | Improper access control in CloudStack's annotation functionality allows unauthor… | |
| CVE-2026-73631 | Low | 0.3% | 4.3 | Exposure of data element to wrong session vulnerability in the JSON plugin of Ap… | |
| CVE-2026-73632 | Low | 0.3% | 4.3 | Exposure of data element to wrong session vulnerability in the JSON plugin of Ap… | |
| CVE-2026-65613 | Low | 0.3% | 4.3 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac… | |
| CVE-2026-60093 | Low | 0.3% | 5.5 | Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake com… | |
| CVE-2026-58156 | Low | 0.2% | 4.9 | Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based… | |
| CVE-2026-71378 | Low | 0.2% | 4.6 | ResourceIsolationRequestCycleListener protects a Wicket application against cros… | |
| CVE-2026-61422 | Low | 0.2% | 4.3 | Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template … | |
| CVE-2026-59244 | Low | 0.2% | 6.5 | Apache Airflow's secrets masker did not mask `var.json` Variable values whose va… | |
| CVE-2026-68970 | Low | 0.2% | 6.5 | Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON val… | |
| CVE-2026-66053 | Low | 0.2% | 5.9 | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Th… | |
| CVE-2026-49267 | Low | 0.2% | 5.9 | Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers … | |
| CVE-2026-44119 | Low | 0.2% | 5.5 | Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and ear… |