These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-82355 debrief: Apache Airflow 3.3.0 and 3.3.1 are vulnerable to principal confusion due to improper handling of session cookies and Authorization headers, allowing an attacker to manipulate audit logs. The vulnerability can be exploited by placing a valid session cookie in the victim's browser or client, which can be achieved through various means such as cookie tossing from a sibling subdomain, [truncated]
A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue. This denial of service vulnerability can be triggered by a malicious pair of WS-Policy documents, potentially leading to significant performance degradation. [truncated]
CVE-2026-91865 is a high-severity vulnerability in Apache Neethi, a WS-Policy document processor. A specially crafted WS-Policy document with repeated policy references can cause Neethi to re-expand the same references exponentially during normalization, leading to a denial of service (DoS) due to excessive CPU and memory consumption. The vulnerability has a CVSS score of 7.5 and is considered high severi [truncated]
CVE-2026-75880 is a denial-of-service vulnerability affecting Apache Artemis and Apache ActiveMQ Artemis. An authenticated client can attach a consumer with a crafted wildcard selector, causing excessive evaluation during message delivery attempts. This issue impacts Apache Artemis versions 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis versions 1.0.0 through 2.44.0. Users are recommended to upgrade to [truncated]
A vulnerability in Apache Artemis allows an authenticated messaging client with MANAGE permission to cause denial of service via Java deserialization. The issue arises when the broker processes message-based management requests, leading to excessive computation and thread pinning. Users are recommended to upgrade to version 2.57.0 to fix the issue. This vulnerability affects Apache Artemis from 2.50.0 thr [truncated]
CVE-2026-49364 is a critical vulnerability in Apache Artemis and Apache ActiveMQ Artemis that allows unauthenticated network-adjacent attackers to capture cluster administrative credentials during the initial cluster connection handshake. Affected product deployments should assess exposure and prioritize upgrading to version 2.57.0. The CVE record was published on 2026-09-10T05:17:01.230Z and has not been [truncated]
CVE-2026-49362 is a high-severity vulnerability affecting Apache Artemis and Apache ActiveMQ Artemis. An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, potentially leading to unauthorized broker state manipulation and denial of service. Affected versions include Apache Artemis from 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis from 1.0.0 through 2.44.0. User [truncated]
CVE-2026-68569 Improper Authentication vulnerability in Apache Tomcat allows authentication of non-existent users in certain circumstances. Affected versions include 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100, and 7.0.0 through 7.0.109. Users should upgrade to version 11.0.25, 10.1.58, or 9.0.121.
CVE-2026-68971 debrief based on the supplied source corpus. Apache Airflow's asset materialization endpoint and XCom result check did not properly authorize target Dags based on team, allowing authenticated users in one team to trigger Dag runs and read XCom values from another team in multi-team mode with team-aware auth managers. The vulnerability affects deployments using multi-team mode with team-awar [truncated]
CVE-2026-68970 debrief: Apache Airflow Variable masking issue exposes secrets in logs and UI due to incomplete masking of JSON list values. Authenticated users with access to logs or rendered templates can recover secrets. The issue is fixed in apache-airflow 3.3.1 or later. This vulnerability is a counterpart to CVE-2026-59244, which only addressed dict-shaped values, leaving list-shaped values unmasked. [truncated]
CVE-2026-68968 debrief: Apache Airflow Backfill API vulnerability allows unauthorized access to backfills due to improper parsing of the `backfill_id` path segment. An authenticated user with edit permission on any single Dag can read, pause, and cancel backfills belonging to any other Dag, potentially disrupting queued runs and elevating privileges. Users should upgrade to apache-airflow 3.3.1 or later t [truncated]
Apache Airflow's environment-variable secrets backend incorrectly resolved team-scoped connections or variables from the wrong team's scope. An authenticated user of one team could exploit this to authenticate outward with another team's credentials via the `POST /api/v2/connections/test` endpoint. This requires multi-team mode, the test connection feature enabled, team-scoped secrets provisioned as envir [truncated]
Apache Airflow's Task SDK is vulnerable to arbitrary module import due to insecure deserialization of Callback objects. A Dag author can cause the scheduler process to import an arbitrary module when deserializing a Callback object, allowing for potential code execution. The vulnerability exists because the Task SDK rebuilds a Callback object from serialized data by re-running its constructor, which impor [truncated]
Apache Airflow 3.3.0 introduced a new `awaiting_input` task state that deserializes task instance `next_kwargs` without an allow-list. This allows a Dag author to cause an arbitrary module import and object instantiation inside the scheduler process or terminate the scheduler job. The sweep runs unconditionally every 15 seconds, and the default `allowed_deserialization_classes` setting does not cover this [truncated]
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI. Users with access to a task's Rendered Templates view could see secret values stored as JSON Variables in cleartext. The issue is fixed in apache-airflow 3.3.1 or later. This vulnerability allows unauthorized access to sensitive information, requiring defenders to assess exposure and [truncated]
Apache Airflow's serialization layer vulnerability allows Dag authors to import and invoke arbitrary callables, potentially leading to security risks. The vulnerability affects Airflow versions prior to 3.3.1 and is distinct from CVE-2026-33264. This vulnerability impacts the Scheduler and API server components, which handle metadata database credentials and the JWT signing secret. Dag authors could explo [truncated]
CVE-2026-54183 debrief: Apache Airflow UI secrets exposure through incomplete secrets masker fix. The vulnerability allows authenticated users to view unmasked sensitive data in the Variables UI. This exposure is limited to the UI and does not disclose data that a user could not otherwise obtain through the Variables REST API. The issue was addressed with apache-airflow 3.3.1 or later, which fixes the rec [truncated]
Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could cause Polaris to use the catalog's storage credentials to read a caller-selected Iceberg metadata file before verifying that the file was within the catalog's allowed storage locations. If the catalog's underlying credentia [truncated]
Apache NiFi 1.10.0 through 2.10.0 has an authorization issue. Clients with read access can submit proposed Parameter values that override current configuration, allowing them to invoke predefined component validation methods with alternative settings. This issue does not affect installations with different authorization levels for viewing and modifying Parameter Context configuration. Upgrading to Apache [truncated]
The CVE-2026-61372 record indicates an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki through version 6.1.0. This issue has a CVSS score of 7.5 and is classified as HIGH. The vulnerability could allow attackers to access sensitive data or execute arbitrary code by traversing directory paths. Users are recommended to upgrade to version 6.2 [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-66756 was published on 2026-07-30T20:18:13.877Z. This Improper Protection of Alternate Path vulnerability affects Apache Tika versions from 4.0.0-alpha-1 before 4.0.0-beta-1, with a CVSS score of 6.9 and MEDIUM severity. Users are recommended to upgrade to version 4.0.0-beta-1. Evidence is limited to CVE and NV [truncated]
The CVE-2026-66755 vulnerability in Apache Tika's ISA-Tab parser allows attackers to read arbitrary files by manipulating the 'Study Assay File Name' in the ISA-Tab investigation file. This Relative Path Traversal vulnerability affects Apache Tika users, administrators of systems where Tika is deployed, and security teams responsible for vulnerability management. Users are recommended to upgrade to versio [truncated]
A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The vulnerability is located in the sql_parse.py component, specifically within the SQL_REGEX used for parsing SQL statements in the sqlparse library integration. An authenticated attacker can exploit this by sending a maliciously crafted input string to endpoints that process SQL queries.
The CVE-2026-23981 Improper Authorization vulnerability in Apache Superset allows authenticated users with chart update permissions to modify dashboards they do not own. This issue arises from insufficient authorization checks in the UpdateChartCommand, potentially leading to unauthorized dashboard modifications. Affected deployments include Apache Superset instances before version 6.0.0. Evidence is limi [truncated]
Apache Traffic Server is vulnerable to a corruption of subsequent header blocks on a connection due to an encoder synchronization issue with the peer decoder after an HTTP/2 HPACK dynamic table update failure. This issue arises from the server's handling of HTTP/2 HPACK dynamic table updates before confirming the header block has been encoded successfully. The vulnerability can lead to an encoder being ou [truncated]
Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability can lead to SSRF amplification attacks, which can have significant [truncated]
Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The CVSS score for this vulnerability is 8.4, indicating a high severity level. Users are recommended to upgrade to version 9.2.15 or 10.1.4. The CVE record was published on 2026-07-29T10:16:44 [truncated]
Apache Traffic Server multiplexer plugin buffer overrun allows denial of service. The vulnerability affects Apache Traffic Server versions from 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4 for a fix. This issue has a CVSS score of 6.3 and a severity of MEDIUM. The vulnerability can be exploited by an attacker sending spe [truncated]
The Apache Traffic Server intercept plugin has a use-after-free vulnerability. This issue affects Apache Traffic Server versions from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, and from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability could potentially lead to exploitation, allowing attackers to execute arbitrary code or cause [truncated]
Apache Traffic Server's ts_lua plugin has a vulnerability due to mishandling of initialization, transform context, and per-instance state. This affects versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The vulnerability has a high CVSS score of 8.2, indicating a high severity level. Users should upgrade to version 9.2.15 or 10.1.4. This issue can lead to significant impact due [truncated]