PatchSiren

Apache Software Foundation CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Apache Software Foundation CVE published 2026-10-02

CVE-2026-66331

CVE-2026-66331 is an Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Delphi bindings buffered transport. This issue affects Apache Thrift before version 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. The vulnerability can lead to potential denial of service or performance degradation. Users of Apache Thrift Delphi bindings buffered tr [truncated]

HIGH Apache Software Foundation CVE published 2026-10-02

CVE-2026-66055

CVE-2026-66055 is an Allocation of Resources Without Limits or Throttling vulnerability affecting Apache Thrift C++, Java, Go, netstd, Python, and Delphi bindings before version 0.25.0. The vulnerability could lead to resource exhaustion if exploited. Users should assess exposure and prioritize upgrading to version 0.25.0 to fix the issue. This involves reviewing affected systems, verifying version number [truncated]

MEDIUM Apache Software Foundation CVE published 2026-10-02

CVE-2026-66054

CVE-2026-66054 is an Allocation of Resources Without Limits or Throttling, Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift before version 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. The vulnerability can lead to resource exhaustion and data amplification attacks. Defenders [truncated]

HIGH Apache Software Foundation CVE published 2026-10-02

CVE-2026-63772

CVE-2026-63772 is an Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift go bindings, affecting versions before 0.25.0. Users should upgrade to version 0.25.0. The CVE record was published on 2026-10-02T13:17:52.640Z and was last modified on 2026-10-03T16:16:37.650Z. This vulnerability could lead to resource exhaustion and potential denial of service (DoS) attacks. Defender [truncated]

HIGH Apache Software Foundation CVE published 2026-10-02

CVE-2026-61374

CVE-2026-61374 is an Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift before version 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. The vulnerability can lead to potential denial of service and performance degradation. Defenders and administrators should assess their exposure and upgrade [truncated]

Review Apache Software Foundation CVE published 2026-10-01

CVE-2026-42356

A security update for EasyApache 4 was released, updating ea-apache24 to Apache HTTP Server 2.4.69, which fixes twenty vulnerabilities, including CVE-2026-42356. This update addresses multiple security issues, and defenders should review the EasyApache 4 change log for a full list of changes. The update is crucial for maintaining the security and integrity of Apache HTTP Server and EasyApache 4 deployment [truncated]

Review Apache Software Foundation CVE published 2026-09-28

CVE-2026-91006

Apache Karaf's instance-management service (InstanceServiceImpl) is vulnerable to arbitrary OS command execution due to improper sanitization of user-supplied input. The vulnerability allows an attacker to inject shell metacharacters and execute arbitrary commands as the Karaf process user. This issue is reachable via several commands and JMX operations, including instance:create, instance:start, instance [truncated]

Review Apache Software Foundation CVE published 2026-09-28

CVE-2026-90979

A vulnerability in LDAPCache and LDAPBackingEngine allows for LDAP search filter injection through unescaped login names, potentially leading to over-granting of roles or incorrect login resolution. This issue arises from insufficient sanitization of login names, allowing crafted usernames to alter the structure of LDAP search filters. The vulnerability affects systems using GSSAPILdapLoginModule or LDAPB [truncated]

MEDIUM Apache Software Foundation CVE published 2026-09-28

CVE-2026-86507

CVE-2026-86507 debrief based on the supplied source corpus. Apache Roller 6.1.5 is vulnerable to improper neutralization of input, allowing an anonymous remote attacker to store a crafted comment-author URL that can execute script in the session of a weblog moderator or global administrator when the comment management page is viewed. This affects sites that permit comments on at least one weblog and whose [truncated]

MEDIUM Apache Software Foundation CVE published 2026-09-28

CVE-2026-91206

CVE-2026-91206 is a reflected cross-site scripting (XSS) vulnerability in Apache Roller 6.1.5. The vulnerability affects sites configured to use the LdapCommentAuthenticator. A remote attacker can exploit this vulnerability by crafting a link that a victim must follow, and the attack is limited to users whose sessions have already loaded the authenticator form. The vulnerability has a CVSS score of 6.1 an [truncated]

MEDIUM Apache Software Foundation CVE published 2026-09-28

CVE-2026-91204

CVE-2026-91204 is a Cross-site Scripting (XSS) vulnerability in Apache Roller 6.1.5. An anonymous remote attacker can store a comment with a javascript: URI link that executes script in the browser of a visitor who clicks it, affecting sites with HTML comments enabled and the HTMLSubset comment formatter. Users should upgrade to Apache Roller 6.1.6 or later.

MEDIUM Apache Software Foundation CVE published 2026-09-28

CVE-2026-82546

CVE-2026-82546 is a Cross-site Scripting vulnerability in Apache Roller 6.1.5. An unauthenticated remote attacker can store a crafted comment-author URL through the incoming Trackback endpoint when a published entry accepts comments and Trackbacks. The shipped Trackback, verification and moderation defaults allow the value to be approved and rendered as an active link; a visitor who clicks the link execut [truncated]

MEDIUM Apache Software Foundation CVE published 2026-09-28

CVE-2026-82387

CVE-2026-82387 is a Cross-site Scripting vulnerability in Apache Roller 6.1.5. A user with media-upload rights can store active content, which a victim can execute by opening the uploaded file. Media uploads are disabled by default, but installations that enable them are affected. The vulnerability allows a user to store active content because the media upload feature trusts the upload-supplied content ty [truncated]

HIGH Apache Software Foundation CVE published 2026-09-28

CVE-2026-82386

CVE-2026-82386 Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows weblog administrators to read files readable by the Roller process and reach internal network addresses by importing a crafted OPML document. This vulnerability is a high-severity issue that can lead to potential unauthorized file access and internal network reconnaissance. Users are recommended to upgrade t [truncated]

MEDIUM Apache Software Foundation CVE published 2026-09-28

CVE-2026-82385

CVE-2026-82385 debrief based on the supplied source corpus. Apache Roller 6.1.5 allows weblog administrators to read sensitive files on the application classpath by authoring Velocity templates that use include directives to load classpath resources outside the theme namespace. This exposure affects any weblog whose administrator can author templates. The vulnerability enables reading of Roller configurat [truncated]

CRITICAL Apache Software Foundation CVE published 2026-09-28

CVE-2026-82384

CVE-2026-82384 is a critical vulnerability in Apache Roller 6.1.5 that allows unauthenticated remote attackers to cause deserialization of attacker-controlled bytes, potentially leading to remote code execution. The issue arises from the XML-RPC endpoint accepting vendor extension types that are deserialized during request parsing before authentication. Users are recommended to upgrade to Apache Roller 6. [truncated]

HIGH Apache Software Foundation CVE published 2026-09-28

CVE-2026-82383

CVE-2026-82383 is a high-severity vulnerability in Apache Roller 6.1.5 that allows unauthenticated remote attackers to change site-global configuration values, potentially redirecting or breaking the site's public frontpage. The vulnerability is caused by a missing authentication check in the setup action, which remains anonymously reachable after installation. This issue affects site administrators and u [truncated]

MEDIUM Apache Software Foundation CVE published 2026-09-28

CVE-2026-82382

CVE-2026-82382 is a reflected cross-site scripting (XSS) vulnerability in Apache Roller 6.1.5. The vulnerability affects weblogs using the bundled frontpage theme. A remote attacker can exploit this vulnerability by supplying a crafted blog-directory parameter that the directory page reflects without proper escaping. Users are recommended to upgrade to Apache Roller 6.1.6 or later.

MEDIUM Apache Software Foundation CVE published 2026-09-28

CVE-2026-82381

CVE-2026-82381 is a Cross-site Scripting vulnerability in Apache Roller 6.1.5. An author with weblog authoring rights can store crafted content that executes in another author's or administrator's browser when viewed. No special configuration is required. Users should upgrade to Apache Roller 6.1.6 or later. This vulnerability affects weblogs with multiple authors or administrators who are not mutually tr [truncated]

HIGH Apache Software Foundation CVE published 2026-09-28

CVE-2026-82380

A Cross-Site Request Forgery (CSRF) vulnerability exists in Apache Roller 6.1.5. This vulnerability allows a remote attacker to cause a logged-in user to perform state-changing actions under the victim's authority. The CSRF validation filters accept a request that does not submit the required salt token, validating instead against a value the server itself generated for the request. No optional feature or [truncated]

HIGH Apache Software Foundation CVE published 2026-09-28

CVE-2026-82379

CVE-2026-82379 is an authentication bypass vulnerability in Apache Roller 6.1.5. An attacker can capture and replay a valid WSSE digest authentication header to gain AtomPub authority. Only installations with the non-default AtomPub API, WSSE authentication, and plaintext-compatible password storage are affected. Users should upgrade to Apache Roller 6.1.6 or later.

CRITICAL Apache Software Foundation CVE published 2026-09-28

CVE-2026-82378

CVE-2026-82378 is a critical vulnerability in Apache Roller 6.1.5's OAuth 1.0a authorization endpoint. An unauthenticated remote attacker can bind an outstanding request token for a site-wide consumer to an arbitrary user account, including administrators, by submitting an unsigned authorization request. This issue only affects installations that configure an OAuth 1.0a site-wide consumer and requires kno [truncated]

CRITICAL Apache Software Foundation CVE published 2026-09-28

CVE-2026-82377

CVE-2026-82377 is a critical vulnerability in Apache Roller 6.1.5 that allows authenticated users to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs. The vulnerability exists because the handlers authenticate the caller but do not verify the caller's permission on the weblog or entry actually affected. This issue only affects install [truncated]

HIGH Apache Software Foundation CVE published 2026-09-28

CVE-2026-82376

CVE-2026-82376 Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing rights on a weblog to cause the server to parse an attacker-influenced trackback response with an XML parser that does not disable external entity resolution, leading to disclosure of files readable by the Roller process. The vulnerability is hidden in the standard UI, but its actio [truncated]

HIGH Apache Software Foundation CVE published 2026-09-28

CVE-2026-82375

CVE-2026-82375 debrief based on CVE Program and NVD records. The vulnerability is a Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5, allowing authenticated users with entry-editing rights to cause outbound HTTP requests to attacker-chosen destinations through legacy outbound Trackback and entry enclosure handling. The vulnerability requires verification of affected versions and remediation effor [truncated]

HIGH Apache Software Foundation CVE published 2026-09-28

CVE-2026-82348

CVE-2026-82348 is an authorization bypass vulnerability in Apache Roller 6.1.5 that allows an authenticated user with authoring rights on one weblog to read, modify, or delete resources belonging to another weblog. This affects multi-user installations where users are intended to be isolated between weblogs. Users are recommended to upgrade to Apache Roller 6.1.6 or later.

MEDIUM Apache Software Foundation CVE published 2026-09-25

CVE-2026-92573

CVE-2026-92573: Apache Qpid Broker-J GZIP decompressor denial of service via memory exhaustion. The vulnerability allows authenticated message producers to exhaust memory via a shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion, and HTTP management JSON rendering. This issue affects Apache Qpid Broker-J through version 10.1.0. Users are recommended to u [truncated]

Review Apache Software Foundation CVE published 2026-09-25

CVE-2026-92564

CVE-2026-92564 is a denial of service vulnerability in Apache Qpid Broker-J through version 10.1.0. A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. Defenders responsible for Apache Qpid Broker-J deployments should assess exposure and prioritize upgrading to version 10.1.1. This issue affects Apache Qpid Broker-J: through 10. [truncated]

HIGH Apache Software Foundation CVE published 2026-09-25

CVE-2026-92560

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service in Apache Qpid Broker-J through 10.1.0. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue. The vulnerability could lead to denial of service attacks if not addressed promptly. Defenders sh [truncated]

HIGH Apache Software Foundation CVE published 2026-09-25

CVE-2026-92550

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service in Apache Qpid Broker-J through 10.1.0. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue. The vulnerability could lead to denial of service attacks if not addressed promptly. Defenders sh [truncated]