VulnSea

Apache has 188 CVEs on record. Cadence is steady at roughly 82 per quarter. The busiest recent month was September 2026 with 46. The median CVSS is 7.5 (high), with 34 rated critical. 4% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 1633 days (7 cases). The dominant weakness classes are CWE-502 (18) and CWE-200 (11). Most affected products: airflow (21), tomcat (21), cxf (11).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
4% vs 1% corpus
Median CVSS
7.5
Publish → KEV
1633 d median(7)
Last 90 days
82 prev 63

Products

  • airflow 21
  • tomcat 21
  • cxf 11
  • thrift 9
  • artemis 8
  • http_server 8
188
Total CVEs
34
Critical
7
CISA KEV
7
Exploited

Apache vulnerabilities

CVEs affecting Apache, newest first. Open any entry for full detail, references, and exploit status.

188 CVEsRSS

CVE-2026-44914High· 7.2
3mo ago

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additio…

▾ Twilightapache · nifiEPSS 0.66%via NVD
CVE-2026-54665Medium· 5.3
3mo ago

Apache NiFi fails to validate proxy host headers when constructing qualified URLs

Apache NiFi fails to validate proxy host headers when constructing qualified URLs

▾ Sunlitapache · org.apache.nifi:nifi-jettyEPSS 0.33%via GHSA
CVE-2026-44911Low
3mo ago

Apache NiFi allows read-only users to submit component configuration verification request

Apache NiFi allows read-only users to submit component configuration verification request

▾ Sunlitapache · org.apache.nifi:nifi-web-apiEPSS 0.52%via GHSA
CVE-2026-32966Critical· 9.8
3mo ago

Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure

Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure

▾ Midnightapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.66%via GHSA
CVE-2026-32967Critical· 9.1
3mo ago

Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks

Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks

▾ Midnightapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.55%via GHSA
CVE-2026-41280Medium· 4.9
3mo ago

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects

▾ Sunlitapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.54%via GHSA
CVE-2026-42357Medium· 6.5
3mo ago

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.

▾ Sunlitapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.49%via GHSA
CVE-2026-47340Medium· 6.5
3mo ago

Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.

Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.

▾ Sunlitapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.55%via GHSA
CVE-2026-49268HighPoC
3mo ago

Apache Shiro: LDAP DN Injection in DefaultLdapRealm

Apache Shiro: LDAP DN Injection in DefaultLdapRealm

▾ Midnightapache · org.apache.shiro:shiro-coreEPSS 0.76%via GHSA
CVE-2026-50645High· 7.5
3mo ago

There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upg…

There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upg…

▾ Twilightapache · cxfEPSS 0.74%via NVD
CVE-2026-50634Medium· 6.5
3mo ago

A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Ty…

A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Ty…

▾ Sunlitapache · cxfEPSS 0.36%via NVD
CVE-2026-50633High· 8.1
3mo ago

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. …

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. …

▾ Twilightapache · cxfEPSS 1.3%via NVD
CVE-2026-50632High· 8.1
3mo ago

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JM…

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JM…

▾ Twilightapache · cxfEPSS 1.1%via NVD
CVE-2026-50631High· 7.4
3mo ago

A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false

A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh…

▾ Twilightapache · cxfEPSS 0.39%via NVD
CVE-2026-50630Medium· 6.5
3mo ago

A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class

A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) charac…

▾ Sunlitapache · cxfEPSS 0.64%via NVD
CVE-2026-50629Medium· 5.3
3mo ago

The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters

The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries,…

▾ Sunlitapache · cxfEPSS 0.70%via NVD
CVE-2026-50628Critical· 9.8
3mo ago

A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address

A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security c…

▾ Midnightapache · cxfEPSS 1.0%via NVD
CVE-2026-50627Critical· 9.1
3mo ago

The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens

The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Reso…

▾ Midnightapache · cxfEPSS 0.78%via NVD
CVE-2026-50623Medium· 4.8
3mo ago

An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed…

An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed…

▾ Sunlitapache · cxfEPSS 0.54%via NVD
CVE-2026-49875Critical· 9.8⚖ disputed
3mo ago

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgr…

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgr…

▾ Midnightapache · cxfEPSS 0.81%via NVD
CVE-2026-25700High· 7.2
3mo ago

Apache Answer: AdminToken not invalidated after admin deactivation

Apache Answer: AdminToken not invalidated after admin deactivation

▾ Twilightapache · github.com/apache/incubator-answerEPSS 0.65%via OSV
CVE-2026-34031Medium· 6.5
3mo ago

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

▾ Sunlitapache · github.com/apache/incubator-answerEPSS 0.64%via OSV
CVE-2026-33582Medium· 6.5
3mo ago

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

▾ Sunlitapache · github.com/apache/incubator-answerEPSS 0.65%via OSV
CVE-2026-34905Medium· 6.5
3mo ago

Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability

▾ Sunlitapache · github.com/apache/incubator-answerEPSS 0.51%via OSV
CVE-2026-34033Medium· 5.4
3mo ago

Apache Answer vulnerable to Cross-site Scripting

Apache Answer vulnerable to Cross-site Scripting

▾ Sunlitapache · github.com/apache/incubator-answerEPSS 0.52%via OSV
CVE-2026-25699Medium· 6.1
3mo ago

Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability

Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability

▾ Sunlitapache · github.com/apache/incubator-answerEPSS 0.57%via OSV
CVE-2026-25688Medium· 6.1
3mo ago

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability

▾ Sunlitapache · github.com/apache/incubator-answerEPSS 0.57%via OSV
CVE-2026-44185High· 7.3
3mo ago

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68,…

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68,…

▾ Twilightapache · http_serverEPSS 1.8%via NVD
CVE-2026-42536High· 7.5PoC
3mo ago

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68…

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68…

▾ Midnightapache · http_serverEPSS 2.7%via NVD
CVE-2026-34355High· 7.5
3mo ago

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

▾ Twilightapache · http_serverEPSS 2.7%via NVD
Apache vulnerabilities (CVEs) — page 4 · VulnSea