com.ctrip.framework.apollo:apollo vulnerabilities
CVEs whose affected-version data names the com.ctrip.framework.apollo:apollo package (maven). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-59955High· 7.5Apollo ConfigService access key authentication bypass via raw config file appId parsing
Apollo ConfigService access key authentication bypass via raw config file appId parsing
▾ Twilightctrip · com.ctrip.framework.apollo:apolloEPSS 0.57%via GHSA
CVE-2026-59954High· 7.5Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching
Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching
▾ Twilightctrip · com.ctrip.framework.apollo:apolloEPSS 0.57%via GHSA
CVE-2025-32781Medium· 6.5Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center
Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center
▾ Sunlitctrip · com.ctrip.framework.apollo:apolloEPSS 0.41%via GHSA