These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could cause Polaris to use the catalog's storage credentials to read a caller-selected Iceberg metadata file before verifying that the file was within the catalog's allowed storage locations. If the catalog's underlying credentia [truncated]
Apache NiFi 1.10.0 through 2.10.0 has an authorization issue. Clients with read access can submit proposed Parameter values that override current configuration, allowing them to invoke predefined component validation methods with alternative settings. This issue does not affect installations with different authorization levels for viewing and modifying Parameter Context configuration. Upgrading to Apache [truncated]
The CVE-2026-61372 record indicates an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki through version 6.1.0. This issue has a CVSS score of 7.5 and is classified as HIGH. The vulnerability could allow attackers to access sensitive data or execute arbitrary code by traversing directory paths. Users are recommended to upgrade to version 6.2 [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-66756 was published on 2026-07-30T20:18:13.877Z. This Improper Protection of Alternate Path vulnerability affects Apache Tika versions from 4.0.0-alpha-1 before 4.0.0-beta-1, with a CVSS score of 6.9 and MEDIUM severity. Users are recommended to upgrade to version 4.0.0-beta-1. Evidence is limited to CVE and NV [truncated]
The CVE-2026-66755 vulnerability in Apache Tika's ISA-Tab parser allows attackers to read arbitrary files by manipulating the 'Study Assay File Name' in the ISA-Tab investigation file. This Relative Path Traversal vulnerability affects Apache Tika users, administrators of systems where Tika is deployed, and security teams responsible for vulnerability management. Users are recommended to upgrade to versio [truncated]
A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The vulnerability is located in the sql_parse.py component, specifically within the SQL_REGEX used for parsing SQL statements in the sqlparse library integration. An authenticated attacker can exploit this by sending a maliciously crafted input string to endpoints that process SQL queries.
The CVE-2026-23981 Improper Authorization vulnerability in Apache Superset allows authenticated users with chart update permissions to modify dashboards they do not own. This issue arises from insufficient authorization checks in the UpdateChartCommand, potentially leading to unauthorized dashboard modifications. Affected deployments include Apache Superset instances before version 6.0.0. Evidence is limi [truncated]
Apache Traffic Server is vulnerable to a corruption of subsequent header blocks on a connection due to an encoder synchronization issue with the peer decoder after an HTTP/2 HPACK dynamic table update failure. This issue arises from the server's handling of HTTP/2 HPACK dynamic table updates before confirming the header block has been encoded successfully. The vulnerability can lead to an encoder being ou [truncated]
Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability can lead to SSRF amplification attacks, which can have significant [truncated]
Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The CVSS score for this vulnerability is 8.4, indicating a high severity level. Users are recommended to upgrade to version 9.2.15 or 10.1.4. The CVE record was published on 2026-07-29T10:16:44 [truncated]
Apache Traffic Server multiplexer plugin buffer overrun allows denial of service. The vulnerability affects Apache Traffic Server versions from 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4 for a fix. This issue has a CVSS score of 6.3 and a severity of MEDIUM. The vulnerability can be exploited by an attacker sending spe [truncated]
The Apache Traffic Server intercept plugin has a use-after-free vulnerability. This issue affects Apache Traffic Server versions from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, and from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability could potentially lead to exploitation, allowing attackers to execute arbitrary code or cause [truncated]
Apache Traffic Server's ts_lua plugin has a vulnerability due to mishandling of initialization, transform context, and per-instance state. This affects versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The vulnerability has a high CVSS score of 8.2, indicating a high severity level. Users should upgrade to version 9.2.15 or 10.1.4. This issue can lead to significant impact due [truncated]
Apache Traffic Server's uri_signing and url_sig plugins can crash or exhaust the stack with attacker input, affecting versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. This issue presents a high severity vulnerability, with a CVSS score of 8.2, and users are strongly advised to upgrade to version 9.2.15 or 10.1.4. The vulnerability allows for potential crashes or stack exhaust [truncated]
The Apache Traffic Server txn_box plugin is vulnerable to a stack overflow attack from attacker-controlled input. This issue affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The affected product or component is Apache Traffic Server, and the vulnerability class is [truncated]
Apache Traffic Server ESI plugin vulnerability allows for unbounded recursion and fetching of attacker-controlled URLs. This issue affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4. The vulnerability is due to a lack of proper bounds checking in the ESI plugin, which allows an attacker t [truncated]
Apache Traffic Server has out-of-bounds writes, path traversal, and use-after-free errors in its Cripts framework. This issue affects Apache Traffic Server from version 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fixes the issue. The vulnerability's technical details indicate that it could lead to significant impact if exploited, given its high CVSS score of 8.3 and HI [truncated]
Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability could lead to performance issues or crashes if exploited. Defenders should review official CVE records, assess depl [truncated]
Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability could allow a remote attacker to potentially execute arbitrary code. Oper [truncated]
Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability is considered critical, with a CVSS score of 9.2, and can lead to crashes and po [truncated]
Apache Traffic Server is vulnerable to an out-of-bounds read while parsing DNS answers. This issue affects Apache Traffic Server versions from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, and from 10.0.0 through 10.1.3. The vulnerability allows attackers to read beyond the bounds of the DNS answer buffer, potentially leading to information disclosure. Users are recommended to upgrade to version 9.2.15 [truncated]
Apache Traffic Server has a vulnerability allowing IP access controls to be bypassed on UDS listeners due to ACL matching errors. This affects versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The issue allows unauthorized access and potential security breaches. Users of Apache Traffic Server, especially those with high security requirements or using versions within the affect [truncated]
Apache Traffic Server, a high-performance caching proxy server, is vulnerable to a stack overflow issue due to mishandling of PROXY protocol input. This vulnerability, affecting versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3, could allow attackers to execute arbitrary code or disrupt service, emphasizing the need for prompt patching. Users are recommended to upgrade to versi [truncated]
Apache Traffic Server can improperly reuse server sessions and tunnels, exposing data across client connections. This issue affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The vulnerability allows for the improper reuse of server sessions and tunnels, potentially leading to data exposure across client connections. Users are recommended to upgrad [truncated]
The CVE-2026-23904 vulnerability affects Apache Kyuubi, specifically versions from 1.8.0 before 1.12.0. This vulnerability allows a remote requester to cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, potentially leading to Server-Side Request Forgery (SSRF) or open-proxy behavior. The vulnerability is addressed by upgrading to version 1.12.0, which disables the proxy by default [truncated]
Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the new request hostname. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability allows for potential security risks if not addressed. It is crucial t [truncated]
Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability can lead to a denial-of-service (DoS) con [truncated]
Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability allows for access-control bypass due to improper handling of ports within URLs a [truncated]
Apache Traffic Server is vulnerable to header aliasing, request smuggling, and policy bypass due to truncation of over-long header names. This issue affects Apache Traffic Server versions from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, and from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4 to fix the issue.
Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability has been publicly disclosed and is considered critical. Affected systems may exp [truncated]
Apache Traffic Server vulnerability CVE-2026-58153 allows for HTTP/2 origin trailers to be forwarded to HTTP/1 clients without proper chunked framing. This issue affects Apache Traffic Server versions from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability occurs when Apache Traffic Server converts HTTP/2 requests to HTTP/1 requests, [truncated]
Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability allows for potential request smuggling attacks due to the improper han [truncated]
Apache Traffic Server is vulnerable to request smuggling when chunked messages are malformed. This issue affects Apache Traffic Server versions from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, and from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability allows attackers to bypass security controls and access sensitive data. It is [truncated]
Apache Traffic Server Improper Access Control vulnerability CVE-2026-41920 affects versions 9.0.0 through 9.1.14 and 10.0.0 through 10.1.3. The vendor advises upgrading to version 9.1.15 or 10.1.4 to address the issue. This Improper Access Control vulnerability can lead to unauthorized access and potential security breaches in Apache Traffic Server installations. Security teams should review and apply the [truncated]
Apache Traffic Server is vulnerable to a stack overflow during redirect handling when following redirects is enabled, caused by copying the client Host header into a fixed-size stack buffer without bounds checking. This issue affects Apache Traffic Server versions from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, and from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1 [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T08:16:30.983Z and has not been modified since then. The CVE-2026-33267 vulnerability is an Improper Input Validation issue in Apache Traffic Server, affecting versions from 9.2.0 through 9.2.14 and from 10.1.0 through 10.1.3. The vulnerability has a CVSS score of 7.7 and is classified as HIGH sev [truncated]
The CVE-2026-24033 record describes an inconsistent interpretation of HTTP requests, also known as HTTP request/response smuggling, in Apache Traffic Server. This issue affects versions from 10.0.0 through 10.1.3 and from 9.0.0 through 9.2.14. The CVSS score is 6.9, indicating a medium severity vulnerability. Users of Apache Traffic Server should be aware of this vulnerability and take necessary actions t [truncated]
Apache Tomcat has an Uncontrolled Resource Consumption vulnerability in its WebSocket chat example, affecting versions 11.0.0-M20 through 11.0.24, 10.1.24 through 10.1.57, and 9.0.89 through 9.0.120. Users who have removed the examples web application are not affected. The issue is fixed in versions 11.0.25, 10.1.58, and 9.0.121. This vulnerability can lead to resource exhaustion, posing a significant ris [truncated]
Apache Neethi 3.2.2 has a vulnerability that allows bypassing the maximum number of normalized policy alternatives via crafted policies, potentially leading to a denial of service attack through resource consumption. This issue arises from the software's inability to properly handle certain policy configurations, which can be exploited to cause resource exhaustion. Users are advised to upgrade to version [truncated]
Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures. This issue may lead to a denial of service attack due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue. The vulnerability arises from the way Apache Neethi handles policy parsing, which can lead to a denial of service attack.
CVE-2026-46452 is an Improper Input Validation vulnerability in Apache NimBLE's Mesh Proxy SAR reassembly. This issue may result in passing broken data toward the application, leading to memory pressure and unstable parsing behavior. The vulnerability affects Apache NimBLE through version 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue. This vulnerability has a CVSS score [truncated]
CVE-2026-45816 is a NULL Pointer Dereference vulnerability in Apache NimBLE, specifically in the LE Long Term Key Request event. The vulnerability requires disabled asserts, which otherwise would trigger before the NULL dereference, and a bogus or misbehaving controller. Due to these conditions, the severity of the issue is considered low. The vulnerability affects Apache NimBLE through version 1.9.0. Use [truncated]
A deserialization of untrusted data vulnerability exists in Apache Fory, potentially allowing class-registration checks to be bypassed during Java lambda deserialization. The issue affects Apache Fory versions before 1.4.0. Users are advised to upgrade to version 1.4.0, which fixes the issue. This vulnerability has a CVSS score of 9.8 and is considered CRITICAL. The vulnerability is related to the lambda [truncated]
CVE-2026-64609 is a critical vulnerability in Apache Fory, a software project formerly known as Apache Fury. The issue allows for an out-of-bounds read via sun.misc.Unsafe, specifically when using out-of-band zero-copy deserialization. This feature is opt-in, meaning applications not using it are not affected. The vulnerability impacts Apache Fory versions from 0.5.0 up to but not including 1.4.0. Users a [truncated]
The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repackaging is done by an Ant script, which is stored in a subdirectory of the configured 'buildRoot' directory. This subdirectory is calculated based on modules coordinates, like the organisation, name or version. If one of the coordinates contains '../' sequenc [truncated]
Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. This allows a user with write access to the source GCS bucket to create an object whose name contains `..` segments and cause the DAG run to write the downloaded [truncated]
CVE-2026-49042 is an Improper Input Validation vulnerability in Apache Camel. The issue affects Apache Camel versions from 4.8.0 through 4.18.2 and from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.18.3 or 4.21.0, which fixes the issue. This vulnerability has a CVSS score of 7.3 and a severity of HIGH. The affected product deployments should be reviewed for potential exposure.
CVE-2026-46588 is an Improper Input Validation vulnerability affecting Apache Camel versions through 4.14.7, from 4.15.0 through 4.18.2, and from 4.19.0 through 4.20.0. This issue can lead to potential security risks if not addressed. Users are advised to upgrade to version 4.14.8, 4.18.3, or 4.21.0 to fix the issue. The CVSS score for this vulnerability is 7.3, indicating a high severity. It is essential [truncated]
CVE-2026-46587 is an Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0. The vulnerability can be exploited via network, with low attack complexity, no privileges required, and no user interaction needed. The CVSS score for this v [truncated]
The CVE record was published on 2026-07-06T09:16:39.280Z and has not been modified since then. The NVD entry is currently Analyzed. This defense-in-depth hardening change affects Apache Camel from version 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, and from 4.19.0 before 4.21.0. The camel-aws2-sns component has a defense-in-depth update to align with sibling strategies by adding an inbound filter rule [truncated]