PatchSiren

Apache CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Apache CVE published 2026-08-06

CVE-2026-64640

Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could cause Polaris to use the catalog's storage credentials to read a caller-selected Iceberg metadata file before verifying that the file was within the catalog's allowed storage locations. If the catalog's underlying credentia [truncated]

HIGH Apache CVE published 2026-08-03

CVE-2026-62354

Apache NiFi 1.10.0 through 2.10.0 has an authorization issue. Clients with read access can submit proposed Parameter values that override current configuration, allowing them to invoke predefined component validation methods with alternative settings. This issue does not affect installations with different authorization levels for viewing and modifying Parameter Context configuration. Upgrading to Apache [truncated]

HIGH Apache CVE published 2026-08-03

CVE-2026-61372

The CVE-2026-61372 record indicates an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki through version 6.1.0. This issue has a CVSS score of 7.5 and is classified as HIGH. The vulnerability could allow attackers to access sensitive data or execute arbitrary code by traversing directory paths. Users are recommended to upgrade to version 6.2 [truncated]

MEDIUM Apache CVE published 2026-07-30

CVE-2026-66756

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-66756 was published on 2026-07-30T20:18:13.877Z. This Improper Protection of Alternate Path vulnerability affects Apache Tika versions from 4.0.0-alpha-1 before 4.0.0-beta-1, with a CVSS score of 6.9 and MEDIUM severity. Users are recommended to upgrade to version 4.0.0-beta-1. Evidence is limited to CVE and NV [truncated]

MEDIUM Apache CVE published 2026-07-30

CVE-2026-66755

The CVE-2026-66755 vulnerability in Apache Tika's ISA-Tab parser allows attackers to read arbitrary files by manipulating the 'Study Assay File Name' in the ISA-Tab investigation file. This Relative Path Traversal vulnerability affects Apache Tika users, administrators of systems where Tika is deployed, and security teams responsible for vulnerability management. Users are recommended to upgrade to versio [truncated]

MEDIUM Apache CVE published 2026-07-30

CVE-2026-23985

A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The vulnerability is located in the sql_parse.py component, specifically within the SQL_REGEX used for parsing SQL statements in the sqlparse library integration. An authenticated attacker can exploit this by sending a maliciously crafted input string to endpoints that process SQL queries.

MEDIUM Apache CVE published 2026-07-30

CVE-2026-23981

The CVE-2026-23981 Improper Authorization vulnerability in Apache Superset allows authenticated users with chart update permissions to modify dashboards they do not own. This issue arises from insufficient authorization checks in the UpdateChartCommand, potentially leading to unauthorized dashboard modifications. Affected deployments include Apache Superset instances before version 6.0.0. Evidence is limi [truncated]

MEDIUM Apache CVE published 2026-07-29

CVE-2026-65100

Apache Traffic Server is vulnerable to a corruption of subsequent header blocks on a connection due to an encoder synchronization issue with the peer decoder after an HTTP/2 HPACK dynamic table update failure. This issue arises from the server's handling of HTTP/2 HPACK dynamic table updates before confirming the header block has been encoded successfully. The vulnerability can lead to an encoder being ou [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58189

Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability can lead to SSRF amplification attacks, which can have significant [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58188

Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The CVSS score for this vulnerability is 8.4, indicating a high severity level. Users are recommended to upgrade to version 9.2.15 or 10.1.4. The CVE record was published on 2026-07-29T10:16:44 [truncated]

MEDIUM Apache CVE published 2026-07-29

CVE-2026-58187

Apache Traffic Server multiplexer plugin buffer overrun allows denial of service. The vulnerability affects Apache Traffic Server versions from 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4 for a fix. This issue has a CVSS score of 6.3 and a severity of MEDIUM. The vulnerability can be exploited by an attacker sending spe [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58185

The Apache Traffic Server intercept plugin has a use-after-free vulnerability. This issue affects Apache Traffic Server versions from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, and from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability could potentially lead to exploitation, allowing attackers to execute arbitrary code or cause [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58182

Apache Traffic Server's ts_lua plugin has a vulnerability due to mishandling of initialization, transform context, and per-instance state. This affects versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The vulnerability has a high CVSS score of 8.2, indicating a high severity level. Users should upgrade to version 9.2.15 or 10.1.4. This issue can lead to significant impact due [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58181

Apache Traffic Server's uri_signing and url_sig plugins can crash or exhaust the stack with attacker input, affecting versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. This issue presents a high severity vulnerability, with a CVSS score of 8.2, and users are strongly advised to upgrade to version 9.2.15 or 10.1.4. The vulnerability allows for potential crashes or stack exhaust [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58180

The Apache Traffic Server txn_box plugin is vulnerable to a stack overflow attack from attacker-controlled input. This issue affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The affected product or component is Apache Traffic Server, and the vulnerability class is [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58178

Apache Traffic Server ESI plugin vulnerability allows for unbounded recursion and fetching of attacker-controlled URLs. This issue affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4. The vulnerability is due to a lack of proper bounds checking in the ESI plugin, which allows an attacker t [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58177

Apache Traffic Server has out-of-bounds writes, path traversal, and use-after-free errors in its Cripts framework. This issue affects Apache Traffic Server from version 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fixes the issue. The vulnerability's technical details indicate that it could lead to significant impact if exploited, given its high CVSS score of 8.3 and HI [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58175

Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability could lead to performance issues or crashes if exploited. Defenders should review official CVE records, assess depl [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58164

Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability could allow a remote attacker to potentially execute arbitrary code. Oper [truncated]

CRITICAL Apache CVE published 2026-07-29

CVE-2026-58161

Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability is considered critical, with a CVSS score of 9.2, and can lead to crashes and po [truncated]

MEDIUM Apache CVE published 2026-07-29

CVE-2026-58160

Apache Traffic Server is vulnerable to an out-of-bounds read while parsing DNS answers. This issue affects Apache Traffic Server versions from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, and from 10.0.0 through 10.1.3. The vulnerability allows attackers to read beyond the bounds of the DNS answer buffer, potentially leading to information disclosure. Users are recommended to upgrade to version 9.2.15 [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58159

Apache Traffic Server has a vulnerability allowing IP access controls to be bypassed on UDS listeners due to ACL matching errors. This affects versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The issue allows unauthorized access and potential security breaches. Users of Apache Traffic Server, especially those with high security requirements or using versions within the affect [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58158

Apache Traffic Server, a high-performance caching proxy server, is vulnerable to a stack overflow issue due to mishandling of PROXY protocol input. This vulnerability, affecting versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3, could allow attackers to execute arbitrary code or disrupt service, emphasizing the need for prompt patching. Users are recommended to upgrade to versi [truncated]

MEDIUM Apache CVE published 2026-07-29

CVE-2026-58157

Apache Traffic Server can improperly reuse server sessions and tunnels, exposing data across client connections. This issue affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The vulnerability allows for the improper reuse of server sessions and tunnels, potentially leading to data exposure across client connections. Users are recommended to upgrad [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-23904

The CVE-2026-23904 vulnerability affects Apache Kyuubi, specifically versions from 1.8.0 before 1.12.0. This vulnerability allows a remote requester to cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, potentially leading to Server-Side Request Forgery (SSRF) or open-proxy behavior. The vulnerability is addressed by upgrading to version 1.12.0, which disables the proxy by default [truncated]

MEDIUM Apache CVE published 2026-07-29

CVE-2026-65325

Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the new request hostname. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability allows for potential security risks if not addressed. It is crucial t [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-65324

Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability can lead to a denial-of-service (DoS) con [truncated]

MEDIUM Apache CVE published 2026-07-29

CVE-2026-58156

Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability allows for access-control bypass due to improper handling of ports within URLs a [truncated]

CRITICAL Apache CVE published 2026-07-29

CVE-2026-58155

Apache Traffic Server is vulnerable to header aliasing, request smuggling, and policy bypass due to truncation of over-long header names. This issue affects Apache Traffic Server versions from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, and from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4 to fix the issue.

CRITICAL Apache CVE published 2026-07-29

CVE-2026-58154

Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability has been publicly disclosed and is considered critical. Affected systems may exp [truncated]

MEDIUM Apache CVE published 2026-07-29

CVE-2026-58153

Apache Traffic Server vulnerability CVE-2026-58153 allows for HTTP/2 origin trailers to be forwarded to HTTP/1 clients without proper chunked framing. This issue affects Apache Traffic Server versions from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability occurs when Apache Traffic Server converts HTTP/2 requests to HTTP/1 requests, [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-58150

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability allows for potential request smuggling attacks due to the improper han [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-57834

Apache Traffic Server is vulnerable to request smuggling when chunked messages are malformed. This issue affects Apache Traffic Server versions from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, and from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability allows attackers to bypass security controls and access sensitive data. It is [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-41920

Apache Traffic Server Improper Access Control vulnerability CVE-2026-41920 affects versions 9.0.0 through 9.1.14 and 10.0.0 through 10.1.3. The vendor advises upgrading to version 9.1.15 or 10.1.4 to address the issue. This Improper Access Control vulnerability can lead to unauthorized access and potential security breaches in Apache Traffic Server installations. Security teams should review and apply the [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-33930

Apache Traffic Server is vulnerable to a stack overflow during redirect handling when following redirects is enabled, caused by copying the client Host header into a fixed-size stack buffer without bounds checking. This issue affects Apache Traffic Server versions from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, and from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1 [truncated]

HIGH Apache CVE published 2026-07-29

CVE-2026-33267

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T08:16:30.983Z and has not been modified since then. The CVE-2026-33267 vulnerability is an Improper Input Validation issue in Apache Traffic Server, affecting versions from 9.2.0 through 9.2.14 and from 10.1.0 through 10.1.3. The vulnerability has a CVSS score of 7.7 and is classified as HIGH sev [truncated]

MEDIUM Apache CVE published 2026-07-29

CVE-2026-24033

The CVE-2026-24033 record describes an inconsistent interpretation of HTTP requests, also known as HTTP request/response smuggling, in Apache Traffic Server. This issue affects versions from 10.0.0 through 10.1.3 and from 9.0.0 through 9.2.14. The CVSS score is 6.9, indicating a medium severity vulnerability. Users of Apache Traffic Server should be aware of this vulnerability and take necessary actions t [truncated]

HIGH Apache CVE published 2026-07-28

CVE-2026-66299

Apache Tomcat has an Uncontrolled Resource Consumption vulnerability in its WebSocket chat example, affecting versions 11.0.0-M20 through 11.0.24, 10.1.24 through 10.1.57, and 9.0.89 through 9.0.120. Users who have removed the examples web application are not affected. The issue is fixed in versions 11.0.25, 10.1.58, and 9.0.121. This vulnerability can lead to resource exhaustion, posing a significant ris [truncated]

HIGH Apache CVE published 2026-07-24

CVE-2026-66143

Apache Neethi 3.2.2 has a vulnerability that allows bypassing the maximum number of normalized policy alternatives via crafted policies, potentially leading to a denial of service attack through resource consumption. This issue arises from the software's inability to properly handle certain policy configurations, which can be exploited to cause resource exhaustion. Users are advised to upgrade to version [truncated]

HIGH Apache CVE published 2026-07-24

CVE-2026-66142

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures. This issue may lead to a denial of service attack due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue. The vulnerability arises from the way Apache Neethi handles policy parsing, which can lead to a denial of service attack.

MEDIUM Apache CVE published 2026-07-24

CVE-2026-46452

CVE-2026-46452 is an Improper Input Validation vulnerability in Apache NimBLE's Mesh Proxy SAR reassembly. This issue may result in passing broken data toward the application, leading to memory pressure and unstable parsing behavior. The vulnerability affects Apache NimBLE through version 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue. This vulnerability has a CVSS score [truncated]

HIGH Apache CVE published 2026-07-24

CVE-2026-45816

CVE-2026-45816 is a NULL Pointer Dereference vulnerability in Apache NimBLE, specifically in the LE Long Term Key Request event. The vulnerability requires disabled asserts, which otherwise would trigger before the NULL dereference, and a bogus or misbehaving controller. Due to these conditions, the severity of the issue is considered low. The vulnerability affects Apache NimBLE through version 1.9.0. Use [truncated]

CRITICAL Apache CVE published 2026-07-21

CVE-2026-64606

A deserialization of untrusted data vulnerability exists in Apache Fory, potentially allowing class-registration checks to be bypassed during Java lambda deserialization. The issue affects Apache Fory versions before 1.4.0. Users are advised to upgrade to version 1.4.0, which fixes the issue. This vulnerability has a CVSS score of 9.8 and is considered CRITICAL. The vulnerability is related to the lambda [truncated]

CRITICAL Apache CVE published 2026-07-21

CVE-2026-64609

CVE-2026-64609 is a critical vulnerability in Apache Fory, a software project formerly known as Apache Fury. The issue allows for an out-of-bounds read via sun.misc.Unsafe, specifically when using out-of-band zero-copy deserialization. This feature is opt-in, meaning applications not using it are not affected. The vulnerability impacts Apache Fory versions from 0.5.0 up to but not including 1.4.0. Users a [truncated]

MEDIUM Apache CVE published 2026-07-15

CVE-2026-26032

The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repackaging is done by an Ant script, which is stored in a subdirectory of the configured 'buildRoot' directory. This subdirectory is calculated based on modules coordinates, like the organisation, name or version. If one of the coordinates contains '../' sequenc [truncated]

HIGH Apache CVE published 2026-07-06

CVE-2026-49297

Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. This allows a user with write access to the source GCS bucket to create an object whose name contains `..` segments and cause the DAG run to write the downloaded [truncated]

HIGH Apache CVE published 2026-07-06

CVE-2026-49042

CVE-2026-49042 is an Improper Input Validation vulnerability in Apache Camel. The issue affects Apache Camel versions from 4.8.0 through 4.18.2 and from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.18.3 or 4.21.0, which fixes the issue. This vulnerability has a CVSS score of 7.3 and a severity of HIGH. The affected product deployments should be reviewed for potential exposure.

HIGH Apache CVE published 2026-07-06

CVE-2026-46588

CVE-2026-46588 is an Improper Input Validation vulnerability affecting Apache Camel versions through 4.14.7, from 4.15.0 through 4.18.2, and from 4.19.0 through 4.20.0. This issue can lead to potential security risks if not addressed. Users are advised to upgrade to version 4.14.8, 4.18.3, or 4.21.0 to fix the issue. The CVSS score for this vulnerability is 7.3, indicating a high severity. It is essential [truncated]

HIGH Apache CVE published 2026-07-06

CVE-2026-46587

CVE-2026-46587 is an Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0. The vulnerability can be exploited via network, with low attack complexity, no privileges required, and no user interaction needed. The CVSS score for this v [truncated]

CRITICAL Apache CVE published 2026-07-06

CVE-2026-56140

The CVE record was published on 2026-07-06T09:16:39.280Z and has not been modified since then. The NVD entry is currently Analyzed. This defense-in-depth hardening change affects Apache Camel from version 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, and from 4.19.0 before 4.21.0. The camel-aws2-sns component has a defense-in-depth update to align with sibling strategies by adding an inbound filter rule [truncated]