CVE-2025-57738High· 7.2▾ TwilightApache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 4.6 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
23%
Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being particularly attractive as the machinery is set for runtime reload. Such a feature has been available for a while, but recently it was discovered that a malicious administrator can inject Groovy code that can be executed remotely by a running Apache Syncope Core instance. Users are recommended to upgrade to version 3.0.14 / 4.0.2, which fix this issue by forcing the Groovy code to run in a sandbox.
syncope >= 2.1.0, < 3.0.14syncope >= 4.0.0, < 4.0.2Upgrade past the affected range:
syncope 4.0.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-104714High· 8.8Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts
CVE-2026-104713Medium· 6.5Allocation of resources without limits or throttling vulnerability in the Apache Struts REST plugin
CVE-2026-104712High· 7.5Asymmetric resource consumption (amplification) vulnerability in Apache Struts
CVE-2026-104711Critical· 9.8Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts
CVE-2026-93546High· 8.8Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declari…
CVE-2026-79768Medium· 5.3Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#…