Apache Apache The Apache Software Foundation

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Apache product.

RSS Feeds for Apache security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Apache products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Apache Sorted by Most Security Vulnerabilities since 2018

Apache HTTP Server307 vulnerabilities

Apache AirFlow188 vulnerabilities

Apache Tomcat186 vulnerabilities
JEE Compliant Servlet Container

Apache Traffic Server112 vulnerabilities

Apache Camel71 vulnerabilities

Apache Superset70 vulnerabilities

Apache CXF69 vulnerabilities

Apache ActiveMQ67 vulnerabilities

Apache OFBiz62 vulnerabilities

Apache NiFi54 vulnerabilities

Apache OpenOffice54 vulnerabilities

Apache Solr43 vulnerabilities
Search engine written in java

Apache Struts37 vulnerabilities

Apache Thrift33 vulnerabilities

Apache InLong32 vulnerabilities

Apache CloudStack32 vulnerabilities

Apache DolphinScheduler32 vulnerabilities

Apache Iotdb31 vulnerabilities

Apache JSPWiki29 vulnerabilities

Apache Tika26 vulnerabilities

Apache Zeppelin26 vulnerabilities

Apache Apisix25 vulnerabilities

Apache Kylin24 vulnerabilities

Apache Answer24 vulnerabilities

Apache Shiro24 vulnerabilities

Apache Kafka23 vulnerabilities

Apache Openmeetings23 vulnerabilities

Apache Hive23 vulnerabilities

Apache Syncope22 vulnerabilities

Apache Fineract22 vulnerabilities

Apache Hadoop21 vulnerabilities

Apache Spark21 vulnerabilities

Apache Plusar20 vulnerabilities

Apache Geode19 vulnerabilities

Apache Linkis18 vulnerabilities

Apache Log4j18 vulnerabilities

Apache Ambari17 vulnerabilities

Apache Zookeeper17 vulnerabilities

Apache Streampark17 vulnerabilities

Apache Hertzbeat16 vulnerabilities

Apache Cassandra16 vulnerabilities

Apache Activemq Artemis15 vulnerabilities

Apache Qpid Broker J15 vulnerabilities

Apache James15 vulnerabilities

Apache JMeter14 vulnerabilities

Apache Guacamole13 vulnerabilities

Apache Druid13 vulnerabilities

Apache Wicket12 vulnerabilities

Apache Karaf12 vulnerabilities

Apache Archiva12 vulnerabilities

Apache Commons Compress12 vulnerabilities

Apache Subversion12 vulnerabilities

Apache Nimble11 vulnerabilities

Apache Fory11 vulnerabilities

Apache Ozone11 vulnerabilities

Apache Ranger11 vulnerabilities

Apache Batik10 vulnerabilities

Apache Couchdb10 vulnerabilities

Apache Pdfbox9 vulnerabilities

Apache Kvrocks9 vulnerabilities

Apache Mina9 vulnerabilities

Apache Mesos9 vulnerabilities

Apache Ignite9 vulnerabilities

Apache Storm9 vulnerabilities

Apache Portable Runtime9 vulnerabilities

Apache Roller8 vulnerabilities

Apache Httpclient8 vulnerabilities

Apache Avro8 vulnerabilities

Apache Mina Sshd8 vulnerabilities

Apache Traffic Control8 vulnerabilities

Apache Drill8 vulnerabilities

Apache Streampipes7 vulnerabilities

Apache Apr Util7 vulnerabilities

Apache Atlas7 vulnerabilities

Apache Impala7 vulnerabilities

Apache Doris7 vulnerabilities

Apache Nuttx6 vulnerabilities

Apache Jena6 vulnerabilities

Apache Allura6 vulnerabilities

Apache Xerces C6 vulnerabilities

Apache Brpc6 vulnerabilities

Apache Commons Configuration6 vulnerabilities

Apache Commons Fileupload6 vulnerabilities

Apache Seata5 vulnerabilities

Apache Poi5 vulnerabilities

Apache Arrow5 vulnerabilities

Apache Axis5 vulnerabilities

Apache Submarine5 vulnerabilities

Recent Apache Security Advisories

Advisory Title Published
2.4.68 13 Vulnerabilities Fixed in Apache HTTP Server 2.4.68 June 8, 2026
2.4.67 11 Vulnerabilities Fixed in Apache HTTP Server 2.4.67 May 4, 2026
2.4.66 5 Vulnerabilities Fixed in Apache HTTP Server 2.4.66 December 4, 2025
2.4.65 Vulnerability Fixed in Apache HTTP Server 2.4.65 July 23, 2025
2.4.64 8 Vulnerabilities Fixed in Apache HTTP Server 2.4.64 July 10, 2025
2.4.62 2 Vulnerabilities Fixed in Apache HTTP Server 2.4.62 July 17, 2024
2.4.61 Vulnerability Fixed in Apache HTTP Server 2.4.61 July 16, 2024
2.4.60 8 Vulnerabilities Fixed in Apache HTTP Server 2.4.60 July 15, 2024
2.4.59 3 Vulnerabilities Fixed in Apache HTTP Server 2.4.59 April 4, 2024
2.4.58 4 Vulnerabilities Fixed in Apache HTTP Server 2.4.58 October 19, 2023

Known Exploited Apache Vulnerabilities

The following Apache vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.
CVE-2026-34486 Exploit Probability: 42.6%
August 4, 2026
Apache ActiveMQ Improper Input Validation Vulnerability Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
CVE-2026-34197 Exploit Probability: 97.2%
April 16, 2026
Apache HTTP Server Improper Escaping of Output Vulnerability Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.
CVE-2024-38475 Exploit Probability: 100.0%
May 1, 2025
Apache Tomcat Path Equivalence Vulnerability Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request.
CVE-2025-24813 Exploit Probability: 99.9%
April 1, 2025
Apache OFBiz Forced Browsing Vulnerability Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.
CVE-2024-45195 Exploit Probability: 100.0%
February 4, 2025
Apache HugeGraph-Server Improper Access Control Vulnerability Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code.
CVE-2024-27348 Exploit Probability: 99.2%
September 18, 2024
Apache OFBiz Incorrect Authorization Vulnerability Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker.
CVE-2024-38856 Exploit Probability: 99.4%
August 27, 2024
Apache OFBiz Path Traversal Vulnerability Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution.
CVE-2024-32113 Exploit Probability: 99.4%
August 7, 2024
Apache Flink Improper Access Control Vulnerability Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface.
CVE-2020-17519 Exploit Probability: 97.9%
May 23, 2024
Apache Superset Insecure Default Initialization of Resource Vulnerability Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configured SECRET_KEY according to installation instructions.
CVE-2023-27524 Exploit Probability: 97.4%
January 8, 2024
Apache ActiveMQ Deserialization of Untrusted Data Vulnerability Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.
CVE-2023-46604 Exploit Probability: 99.7%
November 2, 2023
Apache RocketMQ Command Execution Vulnerability Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content.
CVE-2023-33246 Exploit Probability: 96.6%
September 6, 2023
Apache Tomcat Remote Code Execution Vulnerability Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.
CVE-2016-8735 Exploit Probability: 90.3%
May 12, 2023
Apache Log4j2 Deserialization of Untrusted Data Vulnerability Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
CVE-2021-45046 Exploit Probability: 100.0%
May 1, 2023
Apache Spark Command Injection Vulnerability Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.
CVE-2022-33891 Exploit Probability: 93.1%
March 7, 2023
Apache APISIX Authentication Bypass Vulnerability Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution.
CVE-2022-24112 Exploit Probability: 96.0%
August 25, 2022
Apache CouchDB Insecure Default Initialization of Resource Vulnerability Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges.
CVE-2022-24706 Exploit Probability: 92.4%
August 25, 2022
Apache Tomcat Remote Code Execution Vulnerability When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CVE-2017-12617 Exploit Probability: 100.0%
March 25, 2022
Apache Struts Improper Input Validation Vulnerability Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.
CVE-2013-2251 Exploit Probability: 100.0%
March 25, 2022
Apache Tomcat on Windows Remote Code Execution Vulnerability When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CVE-2017-12615 Exploit Probability: 99.6%
March 25, 2022

Of the known exploited vulnerabilities above, 19 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. The vulnerability CVE-2026-34486: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability is in the top 5% of the currently known exploitable vulnerabilities.

Top 10 Riskiest Apache Vulnerabilities

Based on the current exploit probability, these Apache vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.

Rank CVE EPSS Vulnerability
1 CVE-2021-44228 100.0% Apache Log4j2 Remote Code Execution Vulnerability
2 CVE-2017-5638 100.0% Apache Struts Jakarta Multipart parser exception handling vulnerability
3 CVE-2021-40438 100.0% Apache HTTP Server-Side Request Forgery (SSRF)
4 CVE-2013-2251 100.0% Apache Struts Improper Input Validation Vulnerability
5 CVE-2021-41773 100.0% Apache HTTP Server Path Traversal Vulnerability
6 CVE-2018-11776 100.0% Apache Struts 2.3 to 2.3.34 and 2.5 to 2.5.16 Remote Code Execution Vulnerability
7 CVE-2017-12617 100.0% Apache Tomcat Remote Code Execution Vulnerability
8 CVE-2024-45195 100.0% Apache OFBiz Forced Browsing Vulnerability
9 CVE-2021-45046 100.0% Apache Log4j2 Deserialization of Untrusted Data Vulnerability
10 CVE-2021-42013 100.0% Apache HTTP Server 2.4.49 and 2.4.50 Path Traversal

By the Year

In 2026 there have been 602 vulnerabilities in Apache with an average score of 7.4 out of ten. Last year, in 2025 Apache had 229 security vulnerabilities published. That is, 373 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.11.




Year Vulnerabilities Average Score
2026 602 7.39
2025 229 7.29
2024 275 7.45
2023 274 7.47
2022 228 7.63
2021 212 7.61
2020 160 7.56
2019 163 7.37
2018 155 7.24

It may take a day or so for new Apache vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apache Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-71559 Aug 07, 2026
Deserialization of Untrusted Data in Apache Fory <1.5.0 (Go) Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0 before 1.5.0.  Users of other language implementations are not affected. Users are recommended to upgrade to version 1.5.0, which fixes the issue.
Fory
CVE-2026-71558 Aug 07, 2026
Apache Fory C++ 0.14-1.5 Heap Type Confusion in Deserialization Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to denial of service or arbitrary code execution. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications not using Apache Fory C++ polymorphic smart-pointer deserialization are not affected.
Fory
CVE-2026-71560 Aug 07, 2026
Apache Fory C++ OOB Read in Tagged Integer Deserializer (before 1.5.0) Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications that do not use Apache Fory C++ or do not use tagged integer fields are not affected.
Fory
CVE-2025-49506 Aug 06, 2026
APR-util <=1.6.3 Timing Leak via apr_password_validate APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
CVE-2026-32327 Aug 06, 2026
apr-util stack recursion in XML parsing, fixed in 1.6.4 A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
CVE-2026-34191 Aug 06, 2026
Apache Portable Runtime (APR) v1.6.01.6.3 SQL Injection via apr_dbd_oracle Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
CVE-2026-34501 Aug 06, 2026
Heap BO in Apache APR-util redis client (1.6.0-1.6.3, Fixed 1.6.4) Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
CVE-2026-34502 Aug 06, 2026
Heap Overflow in Apache Portable Runtime Utility memcached client (1.3.0-1.6.3) Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
CVE-2026-57818 Aug 06, 2026
Apache JCacheRace: duplicate code redemption fixed in 4.2.3/4.1.8/3.6.12 A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to versions 4.2.3, 4.1.8 or 3.6.12, which fix this issue.
CXF
CVE-2026-61466 Aug 06, 2026
Apache CXF OAuth2 Client Reg: Unvalidated Scope Self-Assignment (4.2.3) In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
CXF
CVE-2026-63687 Aug 06, 2026
Apache CXF JWT Claim Copy JwtRequestCodeFilter disrupts PKCE (3.6.12/4.1.8/4.2.3) Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can thereby substitute the code_challenge, code_challenge_method, nonce, and state values that were set in the outer HTTP request, undermining PKCE integrity and OpenID Connect replay protection. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
CXF
CVE-2026-65583 Aug 06, 2026
Apache CXF OIDC Token Validation Bypass (selfissued IDs) <4.2.3 Apache CXFs OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not accepted by default in the validator. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fixes this issue.
CXF
CVE-2026-68079 Aug 06, 2026
CXF DefaultEncryptingCodeDataProvider Replay (before 4.2.3/4.1.8/3.6.12) In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once." Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
CXF
CVE-2026-68481 Aug 06, 2026
Apache CXF: Revoked Tokens Introspected Successfully (CVE-2026-68481) In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization server MUST invalidate the token.' and 'introspection of a revoked token MUST return {"active":false}'. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
CXF
CVE-2026-65432 Aug 06, 2026
Apache CXF XXE via imported WSDL/XSD, fixed in 4.2.3/4.1.8/3.6.12 Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <xsd:import> referenced from that top-level WSDL is handed off to WSDL4J, which does not disable DOCTYPE declarations or external entities. As a result, the protections applied to the top-level document do not extend to imported documents, leaving imported WSDL/XSD content vulnerable to XML External Entity (XXE) attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
CXF
CVE-2026-57817 Aug 06, 2026
Apache CXF RP c_hash Validation Flaw fixed in 4.2.3, 4.1.8, 3.6.12 The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
CXF
CVE-2026-66909 Aug 06, 2026
Apache CXF JMS Transport Deserialization RCE (up to 4.2.2) Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
CXF
CVE-2026-64958 Aug 06, 2026
Apache CXF DoS via Large Attachment Headers <4.2.3/4.1.8/3.6.12 An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
CXF
CVE-2026-57819 Aug 06, 2026
Apache CXF Form Param Limit Leak Enables DoS (before 4.2.3/4.1.8/3.6.12) Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, no default limit is set which may lead to denial of service attacks when processing  requests with very large numbers of form parameters. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue by using a default limit of 500 parameters.
CXF
CVE-2026-54225 Aug 06, 2026
Apache CXF DoS via attachment-max-size (before 4.2.3/4.1.8/3.6.12) Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no default placed on this size, meaning that a denial of service attack is possible if the user doesn't explicitly set the limit. Users should update to Apache CXF 4.2.3 or 4.1.8 or 3.6.12 which fixes this problem by imposing a default attachment size limit of 50mb.
CXF
CVE-2026-64640 Aug 06, 2026
Apache Polaris Storage Location Validation Bypass Enables SSR Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration path, cause Polaris to use the catalog's storage credentials to read a caller-selected Iceberg metadata file before verifying that the file was within the catalog's allowed storage locations. If the catalog's underlying credentials could read an object outside that boundary, this could disclose limited information from the object. Polaris could also accept registration metadata located within an allowed location that contained references to storage locations outside the allowed boundary. This second condition did not itself cause Polaris to read the referenced external locations during registration. The demonstrated impact is limited to confidentiality. No unauthorized data modification or availability impact has been demonstrated. The server-side read requires a deployment using S3 credential vending and an object outside the allowed locations that the catalog's underlying storage credentials can read. Exploitation requires an authenticated principal with table- or view-registration privileges.
CVE-2026-60053 Aug 05, 2026
Apache Answer 2.x Admin API Keys Fail Session Expiration Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained usable after the owning administrator was demoted or the account was marked inactive, suspended, or deleted, allowing continued access until the keys were explicitly removed. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Answer
CVE-2026-60023 Aug 05, 2026
Apache Answer 2.0.1 Unauthorized Data Exposure via Read Path Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Deleted or pending answers could be retrieved by unauthorized users through the single-answer read path when the parent question remained visible, exposing answer content that should not have been accessible. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Answer
CVE-2026-50749 Aug 05, 2026
Apache Answer(<=2.0.1) AuthZ Bypass: Edit-Reject Without Review Perm Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Answer
CVE-2026-48912 Aug 05, 2026
Apache Answer 2.0.1 - Authenticated Delete Vulnerability in Avatar-Cleanup Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar-cleanup logic allows any authenticated user to delete other users' uploaded files by supplying their file URLs. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Answer
CVE-2026-48911 Aug 05, 2026
Apache Answer 2.0.1 External-Login Vulnerability Allows Account Takeover Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing authorization check in the external-login email binding flow allows unauthenticated attackers to take over arbitrary user accounts by tricking victims into clicking a crafted confirmation link. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Answer
CVE-2026-48834 Aug 05, 2026
Apache Answer 2.0.1 Improper Length Param Handling - DoS Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticated attackers can cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Answer
CVE-2026-61486 Aug 05, 2026
Stack Buffer Overflow in Apache Lucy Library ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-61485 Aug 05, 2026
Apache Lucy Excessive Size Value Memory Allocation Vulnerability ** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-61484 Aug 05, 2026
Deserialization of Untrusted Data in Apache Lucy (Legacy) ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-61483 Aug 05, 2026
Apache Lucy Uncontrolled Recursion CVE-2026-61483 ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-68080 Aug 05, 2026
Apache Qpid Broker-J 10.0.1 Echo Flow Rate Limit DoS It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Qpid Broker J
CVE-2026-67592 Aug 05, 2026
Apache Qpid ProtonJ2: Transfer Frame Exhaustion (1.1.0) It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue
CVE-2026-67555 Aug 05, 2026
Apache Qpid Proton-Dotnet 1.0.0: Unlimited Transfer Frame DoS It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
CVE-2026-68078 Aug 05, 2026
Apache Qpid Broker-J 10.0.1 DoS via Excessive Transfer Frames It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Qpid Broker J
CVE-2026-66277 Aug 05, 2026
Apache Qpid Proton-J DoS via Unbounded Transfer Frames (0.34.1) It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
CVE-2026-67554 Aug 05, 2026
Apache Qpid Proton-Dotnet 1.0.0 DoS via CPU Overuse in Disposition Frame An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
CVE-2026-68077 Aug 05, 2026
Apache Qpid Broker-J <=10.0.1 - Disposition frame ranges DoS An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Qpid Broker J
CVE-2026-66276 Aug 05, 2026
Apache Qpid Proton-J DoS via Large/Illegal Range Disposition Frame (0.34.1) An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
CVE-2026-67591 Aug 05, 2026
Apache Qpid ProtonJ2 1.1.0 DoS via exceeded session flow control window An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.
CVE-2026-67553 Aug 05, 2026
Apache Qpid Proton-Dotnet DoS via session flow control (1.0.0) An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
CVE-2026-68075 Aug 05, 2026
Apache Qpid Broker-J 10.0.1: Authenticated Session Flow Window Overflow DoS An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Qpid Broker J
CVE-2026-66275 Aug 05, 2026
Apache Qpid Proton-J 0.34.x Authenticated Session Window DOS An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
CVE-2026-67590 Aug 05, 2026
Apache Qpid ProtonJ2 1.1.0 PreAuth StackOverflow via Type Nesting A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.
CVE-2026-67552 Aug 05, 2026
Apache Qpid Proton-Dotnet 1.x: StackOverflowError Causing DoS (before 1.1.0) A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue
CVE-2026-68073 Aug 05, 2026
Apache Qpid Broker-J pre-auth StackOverflow via type nesting - <=10.0.1 A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Qpid Broker J
CVE-2026-66274 Aug 05, 2026
Apache Qpid Proton-J pre-auth CVE-2026-66274 DoS via stack overflow (up to 0.34.1) A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
CVE-2026-67589 Aug 05, 2026
Pre-auth DoS in Qpid ProtonJ2 <= 1.1.0 via Type Size/Count Handling A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.
CVE-2026-67551 Aug 05, 2026
Apache Qpid Proton-Dotnet <=1.0.0: Type size/count overflow DoS pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
CVE-2026-68060 Aug 05, 2026
Apache Qpid Broker-J <=10.0.1 DoS via excessive allocation (pre-auth) A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Qpid Broker J
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.