Apache Apache The Apache Software Foundation

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Apache product.

RSS Feeds for Apache security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Apache products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Apache Sorted by Most Security Vulnerabilities since 2018

Apache HTTP Server328 vulnerabilities

Apache AirFlow222 vulnerabilities

Apache Tomcat208 vulnerabilities
JEE Compliant Servlet Container

Apache Traffic Server112 vulnerabilities

Apache Thrift94 vulnerabilities

Apache Camel83 vulnerabilities

Apache CXF76 vulnerabilities

Apache Superset70 vulnerabilities

Apache ActiveMQ68 vulnerabilities

Apache OFBiz62 vulnerabilities

Apache NiFi59 vulnerabilities

Apache OpenOffice55 vulnerabilities

Apache CloudStack52 vulnerabilities

Apache DolphinScheduler47 vulnerabilities

Apache Syncope44 vulnerabilities

Apache Solr43 vulnerabilities
Search engine written in java

Apache InLong42 vulnerabilities

Apache Struts42 vulnerabilities

Apache Apisix36 vulnerabilities

Apache Iotdb32 vulnerabilities

Apache JSPWiki29 vulnerabilities

Apache Hive27 vulnerabilities

Apache Roller26 vulnerabilities

Apache Zeppelin26 vulnerabilities

Apache Tika26 vulnerabilities

Apache Shiro25 vulnerabilities

Apache Kylin24 vulnerabilities

Apache Answer24 vulnerabilities

Apache Kafka23 vulnerabilities

Apache Openmeetings23 vulnerabilities

Apache Activemq Artemis22 vulnerabilities

Apache Hadoop22 vulnerabilities

Apache Spark22 vulnerabilities

Apache Zookeeper22 vulnerabilities

Apache Fineract22 vulnerabilities

Apache Wicket21 vulnerabilities

Apache Qpid Broker J21 vulnerabilities

Apache Ranger21 vulnerabilities

Apache Plusar20 vulnerabilities

Apache Geode19 vulnerabilities

Apache Karaf19 vulnerabilities

Apache Linkis18 vulnerabilities

Apache Log4j18 vulnerabilities

Apache Ambari17 vulnerabilities

Apache Streampark17 vulnerabilities

Apache Allura16 vulnerabilities

Apache Hertzbeat16 vulnerabilities

Apache Cassandra16 vulnerabilities

Apache Mina Sshd16 vulnerabilities

Apache James15 vulnerabilities

Apache JMeter14 vulnerabilities

Apache Impala14 vulnerabilities

Apache Guacamole13 vulnerabilities

Apache Druid13 vulnerabilities

Apache Subversion12 vulnerabilities

Apache Archiva12 vulnerabilities

Apache Commons Compress12 vulnerabilities

Apache Tapestry11 vulnerabilities

Apache Nimble11 vulnerabilities

Apache Fory11 vulnerabilities

Apache Mina11 vulnerabilities

Apache Ozone11 vulnerabilities

Apache Doris11 vulnerabilities

Apache Wss4j10 vulnerabilities

Apache Batik10 vulnerabilities

Apache Couchdb10 vulnerabilities

Apache Storm9 vulnerabilities

Apache Kvrocks9 vulnerabilities

Apache Mesos9 vulnerabilities

Apache Ignite9 vulnerabilities

Apache Pdfbox9 vulnerabilities

Apache Portable Runtime9 vulnerabilities

Apache Traffic Control8 vulnerabilities

Apache Httpclient8 vulnerabilities

Apache Avro8 vulnerabilities

Apache Drill8 vulnerabilities

Apache Tomcat Native7 vulnerabilities

Apache Apr Util7 vulnerabilities

Apache Atlas7 vulnerabilities

Apache Streampipes7 vulnerabilities

Apache Jena6 vulnerabilities

Apache Brpc6 vulnerabilities

Apache Xerces C6 vulnerabilities

Apache Commons Configuration6 vulnerabilities

Apache Commons Fileupload6 vulnerabilities

Apache Nuttx6 vulnerabilities

Apache Jackrabbit6 vulnerabilities

Apache Seata5 vulnerabilities

Apache Axis5 vulnerabilities

Recent Apache Security Advisories

Advisory Title Published
2.4.69 20 Vulnerabilities Fixed in Apache HTTP Server 2.4.69 October 1, 2026
2.4.68 13 Vulnerabilities Fixed in Apache HTTP Server 2.4.68 June 8, 2026
2.4.67 11 Vulnerabilities Fixed in Apache HTTP Server 2.4.67 May 4, 2026
2.4.66 5 Vulnerabilities Fixed in Apache HTTP Server 2.4.66 December 4, 2025
2.4.65 Vulnerability Fixed in Apache HTTP Server 2.4.65 July 23, 2025
2.4.64 8 Vulnerabilities Fixed in Apache HTTP Server 2.4.64 July 10, 2025
2.4.62 2 Vulnerabilities Fixed in Apache HTTP Server 2.4.62 July 17, 2024
2.4.61 Vulnerability Fixed in Apache HTTP Server 2.4.61 July 16, 2024
2.4.60 8 Vulnerabilities Fixed in Apache HTTP Server 2.4.60 July 15, 2024
2.4.59 3 Vulnerabilities Fixed in Apache HTTP Server 2.4.59 April 4, 2024

Known Exploited Apache Vulnerabilities

The following Apache vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Apache Struts Command Injection Vulnerability Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.
CVE-2016-3081 Exploit Probability: 94.5%
October 8, 2026
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.
CVE-2026-34486 Exploit Probability: 42.6%
August 4, 2026
Apache ActiveMQ Improper Input Validation Vulnerability Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
CVE-2026-34197 Exploit Probability: 97.2%
April 16, 2026
Apache HTTP Server Improper Escaping of Output Vulnerability Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.
CVE-2024-38475 Exploit Probability: 100.0%
May 1, 2025
Apache Tomcat Path Equivalence Vulnerability Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request.
CVE-2025-24813 Exploit Probability: 99.9%
April 1, 2025
Apache OFBiz Forced Browsing Vulnerability Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.
CVE-2024-45195 Exploit Probability: 100.0%
February 4, 2025
Apache HugeGraph-Server Improper Access Control Vulnerability Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code.
CVE-2024-27348 Exploit Probability: 99.2%
September 18, 2024
Apache OFBiz Incorrect Authorization Vulnerability Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker.
CVE-2024-38856 Exploit Probability: 99.4%
August 27, 2024
Apache OFBiz Path Traversal Vulnerability Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution.
CVE-2024-32113 Exploit Probability: 99.9%
August 7, 2024
Apache Flink Improper Access Control Vulnerability Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface.
CVE-2020-17519 Exploit Probability: 97.8%
May 23, 2024
Apache Superset Insecure Default Initialization of Resource Vulnerability Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions.
CVE-2023-27524 Exploit Probability: 97.4%
January 8, 2024
Apache ActiveMQ Deserialization of Untrusted Data Vulnerability Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.
CVE-2023-46604 Exploit Probability: 99.9%
November 2, 2023
Apache RocketMQ Command Execution Vulnerability Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content.
CVE-2023-33246 Exploit Probability: 96.6%
September 6, 2023
Apache Tomcat Remote Code Execution Vulnerability Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.
CVE-2016-8735 Exploit Probability: 90.3%
May 12, 2023
Apache Log4j2 Deserialization of Untrusted Data Vulnerability Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
CVE-2021-45046 Exploit Probability: 100.0%
May 1, 2023
Apache Spark Command Injection Vulnerability Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.
CVE-2022-33891 Exploit Probability: 93.2%
March 7, 2023
Apache APISIX Authentication Bypass Vulnerability Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution.
CVE-2022-24112 Exploit Probability: 96.1%
August 25, 2022
Apache CouchDB Insecure Default Initialization of Resource Vulnerability Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges.
CVE-2022-24706 Exploit Probability: 92.5%
August 25, 2022
Apache Tomcat Remote Code Execution Vulnerability When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CVE-2017-12617 Exploit Probability: 100.0%
March 25, 2022
Apache Struts Improper Input Validation Vulnerability Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.
CVE-2013-2251 Exploit Probability: 100.0%
March 25, 2022

Of the known exploited vulnerabilities above, 19 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. The vulnerability CVE-2026-34486: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability is in the top 5% of the currently known exploitable vulnerabilities.

Top 10 Riskiest Apache Vulnerabilities

Based on the current exploit probability, these Apache vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.

Rank CVE EPSS Vulnerability
1 CVE-2021-44228 100.0% Apache Log4j2 Remote Code Execution Vulnerability
2 CVE-2017-5638 100.0% Apache Struts Jakarta Multipart parser exception handling vulnerability
3 CVE-2021-40438 100.0% Apache HTTP Server-Side Request Forgery (SSRF)
4 CVE-2013-2251 100.0% Apache Struts Improper Input Validation Vulnerability
5 CVE-2021-41773 100.0% Apache HTTP Server Path Traversal Vulnerability
6 CVE-2018-11776 100.0% Apache Struts 2.3 to 2.3.34 and 2.5 to 2.5.16 Remote Code Execution Vulnerability
7 CVE-2024-45195 100.0% Apache OFBiz Forced Browsing Vulnerability
8 CVE-2021-45046 100.0% Apache Log4j2 Deserialization of Untrusted Data Vulnerability
9 CVE-2017-12617 100.0% Apache Tomcat Remote Code Execution Vulnerability
10 CVE-2021-42013 100.0% Apache HTTP Server 2.4.49 and 2.4.50 Path Traversal

By the Year

In 2026 there have been 1011 vulnerabilities in Apache with an average score of 7.4 out of ten. Last year, in 2025 Apache had 229 security vulnerabilities published. That is, 782 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.15.




Year Vulnerabilities Average Score
2026 1011 7.44
2025 229 7.29
2024 275 7.45
2023 274 7.47
2022 228 7.64
2021 212 7.48
2020 160 7.58
2019 163 7.37
2018 155 7.24

It may take a day or so for new Apache vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apache Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-97791 Oct 09, 2026
Apache CXF STSTokenValidator Remote Unauth Token Acceptance (4.2.4) In Apache CXF, STSTokenValidator checks whether a SAML assertion is signed by a trusted certificate before deciding to send it to the STS. That result was stored in one object shared by all requests, so one request could read another's result. A remote, unauthenticated attacker could send a forged assertion signed with an untrusted certificate while legitimate requests were being processed, and it could be accepted as trusted without ever reaching the STS. Only services that use STSTokenValidator to validate SAML tokens without alwaysValidateToSts set are affected.  Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
CXF
CVE-2026-97468 Oct 09, 2026
Apache CXF STSTokenValidator Cache Hash Collision (4.2.4) Apache CXF's STSTokenValidator and Security Token Service (STS) cached validated security tokens under a non-cryptographic 32-bit hash of the token (Java Arrays.hashCode/hashCode()), and treated a cache hit as proof that the presented token had already been validated. An attacker could craft a token (for example a UsernameToken or a self-signed SAML Assertion) whose hash collides with a cached entry. The token would then be accepted without password validation, signature trust verification or a call to the STS. This could let the attacker authenticate as another user and, through STS token validation or renewal, obtain STS-signed tokens for that identity. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
CXF
CVE-2026-86463 Oct 09, 2026
Apache CXF FIQL Parser DoS via Long Query (4KiB limit) Apache CXF's FIQL query parser has a vulnerability in how it searches for operators in query expressions. The search pattern can get stuck trying many combinations when it encounters a long string without an operator, causing the parser to consume excessive CPU time. An attacker can send a crafted query to make the server use up CPU resources, potentially slowing down or stopping other requests. The fix was to limit FIQL expressions to 4 KiB by default, preventing attackers from sending extremely long inputs while still allowing normal queries. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
CXF
CVE-2026-79650 Oct 09, 2026
Apache CXF OIDC RP Open-Redirect (Before 4.2.4) Apache CXFs OIDC relying-party component could redirect users to an attacker-controlled URL after successful authentication. The issue occurs because attacker-controlled state parameters are preserved and later used as redirect targets without validating that the final decoded URI belongs to the RPs origin. Both directly encoded and double-encoded external URLs can trigger the issue, depending on which validation path is used. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
CXF
CVE-2026-78384 Oct 09, 2026
Apache CXF CompressionUtils Inflate Decompression Bomb (Zip Bomb) CompressionUtils.inflate() decompressed attacker-controlled DEFLATE data with no output-size cap. A small (~KB) crafted payload could expand to gigabytes on the heap. Reachable via JWE decryption when zip=DEF (e.g. JoseSessionTokenProvider with RSA-OAEP key wrap) and via SAML redirect/POST binding token inflation in both cases decompression happens before/independent of trust validation. Fix: Added a configurable maximum inflated-size cap (default 10 MiB, org.apache.cxf.compression-max-inflated-size system property) to CompressionUtils.inflate(); aborts with DataFormatException once exceeded. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
CXF
CVE-2026-73179 Oct 09, 2026
Apache CXF 4.* Improper Use of OAuth2 Auth Code Grant Multiple Tokens Improper enforcement of single-use authorization code semantics in the JPA OAuth2 authorization code grant provider in Apache CXFallows a remote attacker to obtain multiple valid access tokens from a single authorization code via concurrent token exchange requests that race the non-atomic find-then-delete operation against a shared relational database under READ_COMMITTED isolation. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fixes this issue.
CXF
CVE-2026-71575 Oct 09, 2026
Apache OIDC max_age Auth Check Bug in OidcClientCodeRequestFilter (4.2.4+ fix) The max_age authentication-freshness check in OidcClientCodeRequestFilter was inoperative due to a milliseconds/seconds unit mismatch and an inverted comparison polarity. Any relying party using setMaxAgeOffset to enforce re-authentication would silently accept sessions of any age, bypassing step-up authentication policies. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
CXF
CVE-2026-71896 Oct 08, 2026
Apache DolphinScheduler Auth Bypass /users/list-all before 3.4.3 An authorization vulnerability in Apache DolphinScheduler allows authenticated users to retrieve other users' account information through the /dolphinscheduler/users/list-all endpoint without the required permissions. The endpoint fails to enforce the necessary authorization checks before returning user account information. As a result, an authenticated user can access account information they are not authorized to view. Successful exploitation may expose sensitive user information and facilitate account enumeration. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
DolphinScheduler
CVE-2026-71895 Oct 08, 2026
CVE-2026-71895: DolphinScheduler 3.x exposes Kubeconfig (before 3.4.3) An authorization vulnerability in Apache DolphinScheduler allows authenticated non-admin users to retrieve Kubernetes configuration data intended for administrator-managed cluster configuration. The exposed kubeconfig data contains credentials that may allow users to authenticate directly to the Kubernetes API outside DolphinScheduler. The impact depends on the permissions granted to the disclosed credentials. If the kubeconfig provides cluster-admin or broadly privileged service-account access, an attacker may read Kubernetes Secrets, create pods, and establish persistent access to the cluster. This issue affects Apache DolphinScheduler: from 3.2.0 before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
DolphinScheduler
CVE-2026-71183 Oct 08, 2026
Auth Bypass: Private Data Source Leak in Apache DolphinScheduler <3.4.3 An authorization vulnerability in Apache DolphinScheduler allows authenticated users to obtain information about data sources they are not authorized to access through the /unauth-datasource and /authed-datasource endpoints. These endpoints fail to enforce the required data source access controls and return sensitive connection information, including data source passwords. As a result, an authenticated user without permission to access a data source can retrieve its connection details and credentials. Successful exploitation exposes sensitive data source information and may enable unauthorized access to the underlying databases using the disclosed credentials. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
DolphinScheduler
CVE-2026-66087 Oct 08, 2026
Apache DolphinScheduler <3.4.3 Auth Bypass via task-instance API An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to operate task instance in projects they are not authorized to access through the  * /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/stop * /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/savepoint This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
DolphinScheduler
CVE-2026-66084 Oct 08, 2026
Apache DolphinScheduler <3.4.3 Authorization Bypass via task-definition Endpoint An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not authorized to access through the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint. The endpoint fails to verify that the task definition identified by code belongs to the project specified by projectCode. An authenticated user can supply the code of a project they are authorized to access together with a task definition code from another project, bypassing project access restrictions and modifying the target task definition and its upstream dependencies. This vulnerability can compromise workflow integrity and disrupt task execution in unauthorized projects.This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
DolphinScheduler
CVE-2026-66082 Oct 08, 2026
Apache DolphinScheduler <3.4.3 Auth Bypass (Project Schedule/Definition) An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to perform unauthorized operations on workflow schedules, workflow definitions, and task instances in other projects. The affected endpoints check permissions against the supplied projectCode but fail to verify that the target resource belongs to that project. An authenticated user with the required permissions in one project can supply that project's code together with a resource identifier from another project, bypassing the target project's access restrictions. The affected endpoints include: * POST /projects/{projectCode}/schedules/{id}/online and /offline: Activate or deactivate workflow schedules in another project. * POST /projects/{projectCode}/workflow-definition/{code}/release: Change the ONLINE/OFFLINE state of workflow definitions in another project. Successful exploitation allows users to alter workflow availability and interfere with task execution in projects they are not authorized to access. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
DolphinScheduler
CVE-2026-92415 Oct 07, 2026
Apache Jackrabbit Unsafe Reflection via WebDAV Client 2.202.23 Use of Externally-Controlled Input to Select Classes or Code vulnerability in Apache Jackrabbit's WebDAV/Davex client. A malicious WebDAV/DavEx server, or an attacker able to intercept the connection, can cause the client to instantiate arbitrary classes from its classpath, which can lead to arbitrary file creation or truncation. Only applications that use jackrabbit-spi2dav (directly or through jackrabbit-jcr2dav) to connect to a remote repository are affected. Jackrabbit servers are not affected. Category: unsafe reflection on wire data (HIGH). This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17. Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.
Jackrabbit
CVE-2026-92414 Oct 07, 2026
Apache Jackrabbit WebDAV Session Fixation via Lock-Token (Pre-2.23.6) : Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with no credential check. This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17. Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.
Jackrabbit
CVE-2026-97146 Oct 07, 2026
Apache YuniKorn <1.10: User Annotation Bypass with Pod Label Apache YuniKorn 1.9.0 and earlier allows bypassing the check for the user annotation by setting a secondary label on the pod. If the pod has the label 'app=yunikorn' the checks limiting the user annotation content are not run. The label is used to identify the YuniKorn application itself in the deployments. The bypass allows any user to specify an arbitrary user info annotation. The arbitrary user information could allow access to a queue that the user normally would not have access to. Quota usage for the queue might be impacted if the application runs in the incorrect queue. User based quota enforcement is also based on the user annotation. User quota tracking could be side stepped even if the application runs in the correct queue. Users are recommended to upgrade to version 1.10.0, which fixes this issue.
CVE-2026-78243 Oct 07, 2026
Apache YuniKorn 1.8+ LDAP Group Resolver OOB Read Crash (Fixed 1.10.0) Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entries.If the LDAP server returns a group membership entry, memberOf attribute, for a user specified in the pod the server crashes if a membership record does not start with "CN=". This only affects install that have the non default LDAP group provider configured.  Users are recommended to upgrade to version 1.10.0, which fixes this issue.
CVE-2026-92393 Oct 07, 2026
Apache YuniKorn <1.10.0: Bypass Label/User Annotation Checks in UPDATE Apache YuniKorn 1.9.0 and earlier does not implement label and user annotation checks for workload UPDATE action bypassing all checks. Workloads in YuniKorn are defined as the following Kubernetes objects: "deployments", "replicasets", "statefulsets", "daemonsets", "jobs", "cronjobs". The CREATE action correctly enforces the checks for all object types. The bypass allows any user to specify an arbitrary user info annotation. The same bypass also allows changing the application ID for the workload. The combination of the two applied in one UPDATE could allow access to a queue that the user normally would not have access to. Quota usage for the queue might be impacted if the application runs in the incorrect queue. User based quota enforcement is also based on the user annotation. User quota tracking could be side stepped even if the application runs in the correct queue. Users are recommended to upgrade to version 1.10.0, which fixes this issue.
CVE-2026-93684 Oct 07, 2026
Impala 4.5.2 Stored XSS via Table Alias in Web UI (upgrade to 4.5.3) An SQL user using Impala up to and including version 4.5.2 with only SELECT permission can put JavaScript in a table alias and make it run in another user's browser when that user opens the query plan in Impala's Web UI. This is stored XSS (CWE-79). Users are recommended to upgrade to version 4.5.3.
Impala
CVE-2026-90466 Oct 07, 2026
Impala 4.5.2 PTH via trusted_jar_paths Path traversal of 'trusted_jar_paths' in Impala 4.5.2 allows an attacker-controlled JAR to be loaded via a relative path where the prefix matches a path specified in 'trusted_jar_paths'. The startup flag 'trusted_jar_paths' references URIs for loading files from local or remote filesystems. Path traversal can't override the schema, but can result in loading a JAR that has been uploaded to a different location in that filesystem via Impala DDLs such as CREATE DATA SOURCE and CREATE TABLE. Path traversal can only be used if a trusted path exists, so this attack requires 'trusted_jar_paths' have a non-empty value configured by the Impala admin. Users are recommended to upgrade to version 4.5.3, which fixes this issue.
Impala
CVE-2026-97720 Oct 07, 2026
Apache Impala 4.5.2 JWT/OAuth Auth Bypass in Executor Webserver Incorrect implementation of JWT/OAuth authentication in Impala executors in Apache Impala versions up to and including 4.5.2 which allows attacked to access resources served by the executor's webserver when that webserver is configured to accept JWT/OAuth tokens.  Bearer token (JWT) signatures are not validated resulting in the webserver accepting any valid JWT. Users are recommended to either disable JWT/OAuth auth for Impala executors or upgrade to version 4.5.3, which fixes this issue.
Impala
CVE-2026-94114 Oct 06, 2026
Apache Commons BCEL Class Name Mapping Vulnerability (before 6.13.0) Symbolic name not mapping to correct class. BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class. This issue affects Apache Commons BCEL: before 6.13.0. Users are recommended to upgrade to version 6.13.0, which fixes the issue.
CVE-2026-59265 Oct 02, 2026
Apache OpenOffice 4.1.16-4.1.16 Java Integration RCE A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user. This issue is expected to be fixed in version 4.1.17, which is in the release candidate phase. Until then, users can mitigate this issue by disabling Java runtime integration in the Preferences dialog. This prevents the attack. If this is not possible, or as an extra precaution, you can avoid opening open untrusted files entirely. Once 4.1.17 is released, upgrade to that version to fix the issue.
OpenOffice
CVE-2026-66054 Oct 02, 2026
Apache Thrift <=0.24: Data Amplification in C++ Bindings Allocation of Resources Without Limits or Throttling, Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-61374 Oct 02, 2026
Apache Thrift Java Resource Exhaustion Before 0.25.0 Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-63772 Oct 02, 2026
Apache Thrift Go Bindings Resource Exhaustion Before 0.25.0 Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift go bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-66055 Oct 02, 2026
Apache Thrift (<0.25.0) Bindings Resource Exhaustion Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift C++, Java, Go, netstd, Python and Delphi bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-66081 Oct 02, 2026
Apache Thrift c_glib Uninitialized Pointer (before 0.25.0) Access of Uninitialized Pointer vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-66331 Oct 02, 2026
Apache Thrift Delphi BufferedTransport Resource Exhaustion before 0.25.0 Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Delphi bindings buffered transport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-66837 Oct 02, 2026
Apache Thrift PHP Bindings: Buffer Overflow <0.25.0 Stack-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in Apache Thrift php bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-66858 Oct 02, 2026
Apache Thrift Recursion Limit Bypass in Python C++ Accelerator (0.24) The protocol skip routine in several Apache Thrift bindings did not apply the binding's recursion limit, so a message that nests unknown fields deeply enough can exhaust the stack. Affected: the Python C++ accelerator (the pure-Python protocols are not affected), the PHP library and its thrift_protocol extension, and the Perl, Lua, Smalltalk and OCaml libraries. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-66859 Oct 02, 2026
Apache Thrift NULL Pointer in c_glib Bindings <0.25.0 NULL Pointer Dereference, Use of Uninitialized Variable vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-83632 Oct 02, 2026
Apache Thrift <0.25.0 Heap Buffer Overflow & Integer Overflow Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-83663 Oct 02, 2026
Apache Thrift Go Bindings Uncontrolled Recursion (pre-0.25.0) Uncontrolled Recursion vulnerability in Apache Thrift go bindings. Both Go transports satisfy a read out of a buffered frame and, when that frame yields no payload bytes, read the next frame and call `Read` again instead of looping. A peer produces such a frame for 4 bytes in `TFramedTransport` (a declared size of zero) or 18 bytes in `THeaderTransport` (a header block that fills the frame), so nothing bounds the depth. The Go stack limit is reached as a `fatal error`, which `recover()` cannot catch, so the whole process dies. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-83745 Oct 02, 2026
Apache Thrift <0.25.0: Node.js/D WS Alloc DoS (Memory Buffer Over-alloc) Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift  nodejs and D lang bindings. Both bindings' WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the bytes have arrived. A single ~14-byte frame therefore commits as much memory as it cares to declare -- measured at 513 MiB against the Node.js server and 2 GiB against the D transport -- and in the Node.js case the connection is left open afterwards, so the frame can simply be sent again. This issue affects Apache Thrift before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-85476 Oct 02, 2026
Apache Thrift <0.25.0 c_glib infinite loop vulnerability Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-96289 Oct 02, 2026
Recursion Vulnerability in Thrift PHP Bindings (before 0.25.0) Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-96287 Oct 02, 2026
Apache Thrift Perl Bindings Inefficient Algorithmic Complexity (before 0.25.0) Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-96286 Oct 02, 2026
Apache Thrift Perl Bindings Uncaught Exception before 0.25.0 Uncaught exception vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-96277 Oct 02, 2026
Apache Thrift Ruby Uncaught Exception before 0.25.0 Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-94658 Oct 02, 2026
Apache Thrift Lua Bindings Inefficient Algorithmic Complexity (before 0.25.0) Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-94657 Oct 02, 2026
Apache Thrift JavaME Unbounded Resource Allocation before 0.25.0 Allocation of resources without limits or throttling vulnerability in Apache Thrift JavaME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-94656 Oct 02, 2026
Apache Thrift Ruby Bindings: Unbounded Resource Allocation Before 0.25.0 Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-94655 Oct 02, 2026
Apache Thrift Lua Bindings DoS via Unbounded Resource Allocation (0.24.0) Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-94654 Oct 02, 2026
Apache Thrift Python Bindings Infinite Loop Vulnerability (before 0.25.0) Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-94653 Oct 02, 2026
Apache Thrift PHP Bindings Inefficient Algorithmic Complexity (before 0.25.0) Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-94652 Oct 02, 2026
Apache Thrift C++ Bindings Memory Leak Before 0.25.0 Missing release of memory after effective lifetime vulnerability in Apache Thrift c++ bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-94648 Oct 02, 2026
Apache Thrift Dart Bindings Resource Exhaustion Before 0.25.0 Allocation of resources without limits or throttling vulnerability in Apache Thrift dart bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-94646 Oct 02, 2026
Prototype Pollution: Apache Thrift Node.js Bindings <0.25.0 Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
CVE-2026-94638 Oct 02, 2026
Apache Thrift PHP Bindings DoS via Unlimited Resource Allocation (<0.25.0) Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Thrift
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.