VulnSea

Apache Software Foundation has 65 CVEs on record. Disclosure cadence is accelerating: 64 in the last 90 days against 1 in the 90 before. The busiest recent month was September 2026 with 62. The median CVSS is 7.8 (high), with 22 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (10) and CWE-862 (6). Most affected products: org.apache.storm:storm-server (8), apache-airflow (5), org.apache.neethi:neethi (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.8
Publish → KEV
Last 90 days
64 prev 1

Products

  • org.apache.storm:storm-server 8
  • apache-airflow 5
  • org.apache.neethi:neethi 5
  • org.apache.syncope.core:syncope-core-provisioning-java 4
  • org.apache.syncope.core:syncope-core-spring 4
  • Apache Nutch 3
Follow Apache Software Foundation:RSS feedSave a search →Embed badge ↗
65
Total CVEs
22
Critical
0
CISA KEV
0
Exploited

Apache Software Foundation vulnerabilities

CVEs affecting Apache Software Foundation, newest first. Open any entry for full detail, references, and exploit status.

65 CVEsRSS

CVE-2026-94301Critical· 9.8
today

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committ…

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committ…

MidnightApache Software Foundation · Apache MINAvia NVD
CVE-2026-82355Medium· 4.2
today

When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer ove…

When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer ove…

SunlitApache Software Foundation · apache-airflowvia NVD
CVE-2026-75158Medium· 4.3
today

Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read

Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. Any authenticated user holding asset-read access could therefore e…

SunlitApache Software Foundation · apache-airflowvia NVD
CVE-2026-86473None
today

Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie

Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout …

SunlitApache Software Foundation · apache-airflowvia NVD
CVE-2026-91865High· 7.5
today

A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgr…

A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgr…

TwilightApache Software Foundation · org.apache.neethi:neethivia NVD
CVE-2026-91867Medium· 4.3
today

When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial of service). User…

When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial of service). User…

SunlitApache Software Foundation · org.apache.neethi:neethivia NVD
CVE-2026-91866High· 7.5
today

A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes…

A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes…

TwilightApache Software Foundation · org.apache.neethi:neethivia NVD
CVE-2026-91863High· 7.5
today

A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service). Users are recommended to upgrade to version 3.2.4, w…

A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service). Users are recommended to upgrade to version 3.2.4, w…

TwilightApache Software Foundation · org.apache.neethi:neethivia NVD
CVE-2026-91864High· 7.5
today

A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to u…

A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to u…

TwilightApache Software Foundation · org.apache.neethi:neethivia NVD
CVE-2026-47321High· 7.5
today

The CompressionFilter class uses ZLib to deflate and inflate data sent and received

The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting size, and create a buffer no matter what. Some compressed data may have a comp…

TwilightApache Software Foundation · org.apache.mina:mina-filter-compressionEPSS 0.29%via NVD
CVE-2026-75157NonePoC
3d ago

Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`

Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any authenticated user who could read a Dag could therefore delete that Dag's queued asset events, silently sup…

TwilightApache Software Foundation · apache-airflowEPSS 0.17%via NVD
CVE-2026-92230High· 7.5
4d ago

Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads

Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLocal value outlives the OSGi bundle that created it, repeated bundle or feature install, updat…

TwilightApache Software Foundation · Apache KarafEPSS 0.40%via NVD
CVE-2026-76646High· 7.5
5d ago

A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentially resulting in a denial of service condition. Older unsupported versions may also be affected. Users are recomme…

A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentially resulting in a denial of service condition. Older unsupported versions may also be affected. Users are recomme…

TwilightApache Software Foundation · Apache MyFacesEPSS 0.51%via NVD
CVE-2026-68536Critical· 9.8
5d ago

Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affected.  Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.

Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affected.  Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.

MidnightApache Software Foundation · org.apache.myfaces.core:myfaces-implEPSS 0.47%via NVD
CVE-2026-87802Critical· 9.1
1w ago

Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permission…

Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permission…

MidnightApache Software Foundation · org.apache.syncope:syncope-sraEPSS 0.26%via NVD
CVE-2026-87785Critical· 9.1
1w ago

Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's privileges after comp…

Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's privileges after comp…

MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-springEPSS 0.51%via NVD
CVE-2026-87779High· 7.5
1w ago

Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length (not 16/24/32 bytes) is configured, Syncope will pad the provided value with random characters

Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length (not 16/24/32 bytes) is configured, Syncope will pad the provided value with random characters. The resulting key va…

TwilightApache Software Foundation · org.apache.syncope.core:syncope-core-springEPSS 0.41%via NVD
CVE-2026-86460Critical· 9.8
1w ago

Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. U…

Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. U…

MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-persistence-neo4jEPSS 0.56%via NVD
CVE-2026-72524High· 8.8
1w ago

Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access or modify data they are not authorized to. This issue affects Apache Doris: from 3.1.0 through 3.1.*, from 4.0.0 …

Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access or modify data they are not authorized to. This issue affects Apache Doris: from 3.1.0 through 3.1.*, from 4.0.0 …

TwilightApache Software Foundation · Apache DorisEPSS 0.35%via NVD
CVE-2026-68570Medium· 6.5
1w ago

Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data they are not authorized to read, resulting in unauthorized disclosure of information. This issue affects Apa…

Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data they are not authorized to read, resulting in unauthorized disclosure of information. This issue affects Apa…

SunlitApache Software Foundation · Apache DorisEPSS 0.38%via NVD
CVE-2026-82232Critical· 9.8
1w ago

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging u…

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging u…

MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-persistence-jpaEPSS 0.56%via NVD
CVE-2026-78336High· 7.5
1w ago

Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser

Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains al…

TwilightApache Software Foundation · org.apache.syncope.ext.oidcc4ui:syncope-ext-oidcc4ui-logicEPSS 0.41%via NVD
CVE-2026-78330Critical· 9.8
1w ago

Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a succ…

Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a succ…

MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-springEPSS 0.60%via NVD
CVE-2026-78318Medium· 6.1
1w ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. The notification message, as optionally shown by Console's and Enduser's login pages can be instructed to display HT…

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. The notification message, as optionally shown by Console's and Enduser's login pages can be instructed to display HT…

SunlitApache Software Foundation · org.apache.syncope.client.idrepo:syncope-client-idrepo-common-uiEPSS 0.25%via NVD
CVE-2026-77883Medium· 4.9
1w ago

Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficien…

Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficien…

SunlitApache Software Foundation · org.apache.syncope.core:syncope-core-provisioning-apiEPSS 0.38%via NVD
CVE-2026-77181Critical· 9.8
1w ago

Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unable to perform the related operation, while ClientApp's create entitlement is checked both for create and update opera…

Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unable to perform the related operation, while ClientApp's create entitlement is checked both for create and update opera…

MidnightApache Software Foundation · org.apache.syncope.core.am:syncope-core-am-logicEPSS 0.48%via NVD
CVE-2026-77051Critical· 9.8
1w ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging…

MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-persistence-jpaEPSS 0.56%via NVD
CVE-2026-73668Critical· 9.8
1w ago

Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given Realm may be able to read via REST the full Connector configuration, confidential properties included, scoped in another…

Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given Realm may be able to read via REST the full Connector configuration, confidential properties included, scoped in another…

MidnightApache Software Foundation · org.apache.syncope.core.idm:syncope-core-idm-logicEPSS 0.48%via NVD
CVE-2026-73579Critical· 9.8
1w ago

Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elasticsearch / Opensearch queries, depending on the actual deployment configuration. An important component of such trans…

Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elasticsearch / Opensearch queries, depending on the actual deployment configuration. An important component of such trans…

MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-persistence-commonEPSS 0.48%via NVD
CVE-2026-75030Critical· 9.8
1w ago

Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities. This issue…

Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities. This issue…

MidnightApache Software Foundation · org.apache.syncope.core.idrepo:syncope-core-idrepo-logicEPSS 0.58%via NVD
Apache Software Foundation vulnerabilities (CVEs) · VulnSea