PatchSiren

Apache Software Foundation CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Apache Software Foundation CVE published 2026-08-15

CVE-2026-73635

An executive overview of CVE-2026-73635: Apache Struts users should be aware of an allocation of resources without limits or throttling vulnerability. This vulnerability can cause the framework's internal localized-text caches to grow without bound and exhaust the Java heap, denying service to other users. The CVE record was published on 2026-08-15T11:16:27.540Z and has not been modified since then. Affec [truncated]

Review Apache Software Foundation CVE published 2026-08-15

CVE-2026-73634

The CVE-2026-73634 record describes an uncontrolled resource consumption vulnerability in Apache Struts, affecting versions from 6.0.0 through 6.10.0 and from 7.0.0 through 7.2.1. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, allowing a single request to exhaust the heap and deny [truncated]

Review Apache Software Foundation CVE published 2026-08-10

CVE-2026-61899

A vulnerability exists in Apache Tapestry 5.5.0+ on all platforms, allowing attackers to download classpath assets via specially crafted URLs. This issue poses a significant risk to users of Apache Tapestry 5.5.0+ as it could potentially lead to unauthorized access to sensitive data. Users are recommended to upgrade to version 5.9.1, which fixes this issue. It is crucial for operators, platform administra [truncated]

Review Apache Software Foundation CVE published 2026-08-10

CVE-2026-55814

CVE-2026-55814 is a missing authentication issue in Apache Ranger Download APIs versions <= 2.8.0. This vulnerability allows unauthorized access to download APIs, potentially impacting system security and data integrity. Apache Ranger users and administrators should verify their systems for potential exposure and review system configurations. The issue has not been modified since its publication on 2026-0 [truncated]

Review Apache Software Foundation CVE published 2026-08-10

CVE-2026-44416

CVE-2026-44416 is a Remote Code Execution vulnerability via Arbitrary Class Instantiation in the plugin-schema-registry component of Apache Ranger versions <= 2.8.0. This vulnerability allows attackers to execute arbitrary code, potentially leading to a complete compromise of the affected system. The CVE record was published on 2026-08-10T11:17:26.547Z and has not been modified since then. However, the fu [truncated]

Review Apache Software Foundation CVE published 2026-08-10

CVE-2026-42537

CVE-2026-42537 is a Remote Code Execution vulnerability via JDBC URL Injection in Apache Ranger versions <= 2.8.0. The issue is addressed in version 2.9.0. Apache Ranger users should prioritize upgrading to version 2.9.0 and review JDBC URL configurations to prevent exploitation. Limited evidence suggests Apache Ranger users should verify affected deployments, review compensating controls, and monitor for [truncated]

Review Apache Software Foundation CVE published 2026-08-10

CVE-2026-44630

Apache IoTDB RPC service vulnerability allows remote unauthenticated attackers to cause denial of service via crafted Thrift frame. Affected versions: Apache IoTDB before 1.3.8, 2.0.0 to 2.0.9. Upgrade to 2.0.10 to fix. The vulnerability is caused by improper validation of length fields in the Apache IoTDB RPC service, which can lead to excessive memory allocation and a crash with an OutOfMemoryError. Sec [truncated]

HIGH Apache Software Foundation CVE published 2026-08-06

CVE-2026-34502

CVE-2026-34502 is a heap-based buffer overflow vulnerability in the Apache Portable Runtime Utility (APR-Util) memcached client, affecting versions from 1.3.0 through 1.6.3. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. The CWE associated with this vulnerability is CWE-122. The vulnerability can be exploited by sending a specially crafted request to the memcached client, po [truncated]

CRITICAL Apache Software Foundation CVE published 2026-08-06

CVE-2026-34191

The CVE record for CVE-2026-34191 was published on 2026-08-06T15:16:54.650Z and has not been modified since then. The NVD entry is currently Analyzed. This SQL injection vulnerability in Apache Portable Runtime Utility has a critical CVSS score of 9.1 and requires immediate attention. Organizations using affected versions should prioritize patching to prevent potential SQL injection attacks. The vulnerabi [truncated]

HIGH Apache Software Foundation CVE published 2026-08-06

CVE-2026-68481

Apache CXF's DefaultEncryptingOAuthDataProvider incorrectly handles revoked access and refresh tokens, allowing them to decrypt successfully and be reported as active by TokenIntrospectionService, contrary to RFC requirements. This vulnerability affects users of Apache CXF, particularly those using DefaultEncryptingOAuthDataProvider for token management. The issue involves improper invalidation of revoked [truncated]

CRITICAL Apache Software Foundation CVE published 2026-08-06

CVE-2026-68079

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T12:16:28.060Z and has not been modified since then. Apache CXF's DefaultEncryptingCodeDataProvider has a flaw in the implementation of the removeCodeGrant functionality, allowing a captured authorization code to be redeemed an unlimited number of times. This violates the RFC requirement that 'The [truncated]

CRITICAL Apache Software Foundation CVE published 2026-08-06

CVE-2026-65583

Apache CXF's OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, self-issued ID tokens are not accepted by default in the validator. The vulnerability's technical impact is significant, as it allows for potential authentication bypass. [truncated]

CRITICAL Apache Software Foundation CVE published 2026-08-06

CVE-2026-63687

Apache CXF's JwtRequestCodeFilter vulnerability allows a client with a validly-signed request JWT to substitute sensitive values, undermining PKCE integrity and OpenID Connect replay protection. Affected product deployments should be reviewed for potential security risks. The CVE record was published on 2026-08-06T12:16:27.843Z and has not been modified since then. This issue affects Apache CXF users, sec [truncated]

CRITICAL Apache Software Foundation CVE published 2026-08-06

CVE-2026-61466

Apache CXF's OAuth2 Dynamic Client Registration endpoint is vulnerable due to lack of validation against an AS-defined allowlist, potentially allowing scope elevation. Affected product deployments should be identified and reviewed for exposure. The CVE record was published on 2026-08-06T12:16:27.730Z. Users should review the official advisory and plan vendor-supported updates or mitigations.

CRITICAL Apache Software Foundation CVE published 2026-08-06

CVE-2026-66909

Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserial [truncated]

HIGH Apache Software Foundation CVE published 2026-08-06

CVE-2026-65432

Apache CXF is vulnerable to XML External Entity (XXE) attacks due to improper handling of imported WSDL/XSD content. The vulnerability exists because while the top-level WSDL is processed with protections against XML DTDs and external entities, any imported documents are handled by WSDL4J without these protections. This issue affects users of Apache CXF, especially those using versions prior to 3.6.12, 4. [truncated]

HIGH Apache Software Foundation CVE published 2026-08-06

CVE-2026-57817

Apache CXF OpenID Connect Hybrid Flow vulnerability. The OpenID Connect Core 1.0 specification requires validation of the `c_hash` parameter in Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP is vulnerable to Authorization Code Substitution/Injection attacks. Users should upgrade to versions 4.2.3, 4.1.8, or 3.6.12.

HIGH Apache Software Foundation CVE published 2026-08-06

CVE-2026-54225

The CVE-2026-54225 vulnerability affects Apache CXF, a popular open-source services framework. This denial of service vulnerability arises from the lack of a default limit on attachment size, allowing attackers to perform denial of service attacks if users don't explicitly set a limit. The update introduces a default attachment size limit of 50mb in Apache CXF versions 4.2.3, 4.1.8, and 3.6.12. Users of A [truncated]

CRITICAL Apache Software Foundation CVE published 2026-08-05

CVE-2026-60053

Insufficient Session Expiration vulnerability in Apache Answer allows continued access with Administrative API keys after administrator demotion or account inactivation until keys are explicitly removed. This issue affects Apache Answer versions through 2.0.1, posing a medium risk to administrators and users who have not upgraded to version 2.0.2. The vulnerability enables unauthorized access due to the l [truncated]

HIGH Apache Software Foundation CVE published 2026-08-05

CVE-2026-60023

The CVE-2026-60023 vulnerability in Apache Answer through version 2.0.1 allows unauthorized users to retrieve deleted or pending answers when the parent question remains visible. This Exposure of Sensitive Information vulnerability can have significant operational impacts if not properly mitigated. Affected users should upgrade to version 2.0.2 to prevent unauthorized access to sensitive information. This [truncated]

HIGH Apache Software Foundation CVE published 2026-08-05

CVE-2026-48911

The CVE-2026-48911 vulnerability is an Insufficient Verification of Data Authenticity issue in Apache Answer through version 2.0.1. A missing authorization check in the external-login email binding flow allows unauthenticated attackers to take over arbitrary user accounts by tricking victims into clicking a crafted confirmation link. This issue affects Apache Answer through version 2.0.1, and users are re [truncated]

HIGH Apache Software Foundation CVE published 2026-08-05

CVE-2026-48834

The CVE-2026-48834 record describes an Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer through version 2.0.1. This allows unauthenticated attackers to cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing. Organizations should review their deployments and consider upgrading to mitigate potential impacts.

HIGH Apache Software Foundation CVE published 2026-08-05

CVE-2026-61485

This PatchSiren debrief is based on the supplied source corpus for CVE-2026-61485, which describes a Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. The CVE record was published on 2026-08-05T08:16:35.610Z and has not been modified since then. The NVD entry is currently empty. Organizations using Apache Lucy or its components should be aware of this vulnerability. Given that the [truncated]

HIGH Apache Software Foundation CVE published 2026-08-05

CVE-2026-61483

CVE-2026-61483 is an Uncontrolled Recursion vulnerability in Apache Lucy, affecting all versions. The project is retired, and no fix is planned. Users of Apache Lucy should be aware of the vulnerability and take necessary actions to protect their systems. This includes assessing usage, considering migration, and restricting access if needed. The CVE record was published on 2026-08-05T08:16:35.330Z and has [truncated]

MEDIUM Apache Software Foundation CVE published 2026-08-05

CVE-2026-68080

An authenticated attacker could cause excessive resource usage and potential denial of service due to a lack of rate governance for echo flow responses from the broker. This issue affects Apache Qpid Broker-J through 10.0.1. Users are recommended to upgrade to version 10.1.0. The vulnerability can be mitigated by upgrading to version 10.1.0, which fixes the issue. The broker did not govern the rate at whi [truncated]

MEDIUM Apache Software Foundation CVE published 2026-08-05

CVE-2026-68078

Apache Qpid Broker-J vulnerability CVE-2026-68078 allows authenticated attackers to cause excessive resource usage and potential denial of service due to lack of governance on the maximum number of transfer frames per incoming delivery. This issue affects Apache Qpid Broker-J through version 10.0.1, and users are recommended to upgrade to version 10.1.0. Operators, platform administrators, and security te [truncated]

MEDIUM Apache Software Foundation CVE published 2026-08-05

CVE-2026-68075

An authenticated attacker could exceed the session flow control incoming window, potentially leading to denial of service. This issue affects Apache Qpid Broker-J through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue. The vulnerability is related to session flow control, and defenders should review Apache Qpid Broker-J deployments and plan upgrades.

MEDIUM Apache Software Foundation CVE published 2026-08-05

CVE-2026-67555

The CVE-2026-67555 issue is a denial of service vulnerability in Apache Qpid Proton-Dotnet through 1.0.0. An authenticated attacker can cause excessive resource usage and potential denial of service by not governing the maximum number of transfer frames per incoming delivery. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. Users are recommended to upgrade to version 1.1.0. The CVE record was p [truncated]

MEDIUM Apache Software Foundation CVE published 2026-08-05

CVE-2026-66277

CVE-2026-66277 was reported in Apache Qpid Proton-J, where an authenticated user could cause excessive resource usage and potential denial of service due to a lack of governance on the maximum number of transfer frames per incoming delivery. The issue affects Apache Qpid Proton-J through version 0.34.1. Users are recommended to upgrade to version 0.35.0. AI-assisted PatchSiren debrief based on the supplie [truncated]

MEDIUM Apache Software Foundation CVE published 2026-08-05

CVE-2026-66276

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. The vulnerability can lead to a denial of service, potentially impacting system availability and requiri [truncated]

HIGH Apache Software Foundation CVE published 2026-08-05

CVE-2026-68060

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service in Apache Qpid Broker-J through 10.0.1. This denial of service vulnerability can impact the availability of the system, potentially leading to service disruptions. Users are recommended to upgrade to version 10.1.0 to mitigate this issue. Additionally, defenders should [truncated]

Known exploited Apache Software Foundation CVE published 2026-08-04

CVE-2026-34486

A regression vulnerability in Apache Tomcat's EncryptInterceptor allows bypass of encryption protections for sensitive data in transit. The flaw was introduced by the fix for CVE-2026-29146, creating a missing encryption condition (CWE-311) that exposes confidential data to network adversaries. Affected versions are 9.0.116, 10.1.53, and 11.0.20. The vulnerability carries a HIGH severity CVSS 7.5 score wi [truncated]

HIGH Apache Software Foundation CVE published 2026-08-03

CVE-2026-68981

The CVE-2026-68981 vulnerability affects Apache NiFi 1.5.0 through 2.10.0, allowing malicious clients to send crafted gzip-encoded HTTP requests that could consume excessive amounts of memory due to improper handling of decompressed payloads. Organizations should verify their deployments, review the official advisory and CVE record to validate affected scope, severity, and vendor guidance, and consider up [truncated]

LOW Apache Software Foundation CVE published 2026-08-03

CVE-2026-68980

Apache NiFi 2.0.0 through 2.10.0 has a vulnerability related to asset deletion authorization. The framework authorizes asset deletion against the owning Parameter Context using a supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. This issue can be mitigated by upgrading to Apache NiFi 2.11.0, which verifies Parameter Context ownership of the req [truncated]

MEDIUM Apache Software Foundation CVE published 2026-08-03

CVE-2026-68979

Apache NiFi 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and write privileges on the Parameter Context itself. As a result of the missing authorizatio [truncated]

HIGH Apache Software Foundation CVE published 2026-07-31

CVE-2026-62391

The CVE-2026-62391 record details an incomplete security fix for CVE-2025-66518, affecting Apache Kyuubi from version 1.6.0 to before 1.12.0. This allows clients to bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. Apache Kyuubi users and administrators should be aware of the potential security risks and take necessary actions to mitigate them.

MEDIUM Apache Software Foundation CVE published 2026-07-31

CVE-2026-44615

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T11:17:10.087Z and has not been modified since then. CVE-2026-44615 is a path traversal vulnerability in Apache Zeppelin's FileSystemNotebookRepo configuration. An authenticated attacker with permission to rename notes or access folder operations could supply traversal segments in note or folder p [truncated]

CRITICAL Apache Software Foundation CVE published 2026-07-30

CVE-2026-52680

The CVE-2026-52680 vulnerability affects Apache Kyuubi, a software component used for data processing and management. The vulnerability class is related to path traversal in the REST batch multipart upload handling, allowing remote attackers to write controlled content outside the intended upload directory. The likely operational impact is high, as it can lead to arbitrary file writes, potentially allowin [truncated]

MEDIUM Apache Software Foundation CVE published 2026-07-30

CVE-2026-44617

The CVE-2026-44617 record describes an LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm uses RFC 4514 distinguished-name escaping when constructing LDAP search filters instead of RFC 4515 filter escaping. This leaves special filter characters insufficiently escaped, allowing for potential attacks. The issue affects Apache Zeppelin versions 0.11.1, 0.11.2, and 0.12.0. Users are recommended [truncated]

MEDIUM Apache Software Foundation CVE published 2026-07-30

CVE-2026-44616

The CVE-2026-44616 record indicates an LDAP injection vulnerability in Apache Zeppelin, specifically in the ActiveDirectoryGroupRealm when constructing LDAP search filters without escaping user-controlled input. This issue affects versions 0.6.0 through 0.12.0, and users are recommended to upgrade to version 0.12.1. The vulnerability allows an authenticated attacker to inject LDAP filter syntax through th [truncated]

HIGH Apache Software Foundation CVE published 2026-07-30

CVE-2026-28813

Apache JSPWiki up to 2.12.3 is vulnerable to JSON Hijacking, leading to CSRF vulnerabilities. The vulnerability has a CVSS score of 8.8 and is classified as HIGH. Users are recommended to upgrade to version 2.12.4, which fixes this issue. However, the specific details of the vulnerability and its potential impact are not well understood at this time. Affected deployments should be identified and owners as [truncated]

CRITICAL Apache Software Foundation CVE published 2026-07-30

CVE-2026-28812

Apache JSPWiki up to 2.12.3 has a UserManager impersonation vulnerability CVE-2026-28812, with a CVSS score of 9.8. This vulnerability allows attackers to escalate privileges due to a lack of checks in the UserManager. The affected product is Apache JSPWiki up to version 2.12.3, and the vulnerability class is impersonation. The likely operational impact is privilege escalation. The source-confidence limit [truncated]

HIGH Apache Software Foundation CVE published 2026-07-30

CVE-2026-28811

The CVE-2026-28811 issue involves Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. This vulnerability allows attackers to access sensitive information through debug messages, potentially leading to information disclosure. The issue has a CVSS score of 7.5 and is classified as HIGH severity. Users are recommended to upgrade to version 2.12.4, which fixes this issue. Operator [truncated]

CRITICAL Apache Software Foundation CVE published 2026-07-29

CVE-2026-59243

The CVE record for CVE-2026-59243 was published on 2026-07-29T10:16:44.390Z. The vulnerability affects the FAB auth manager's Azure AD OAuth login, which defaulted to `verify_signature=False` when decoding the ID token. This allowed an attacker to bypass authentication with a forged or unsigned ID token. The issue affects `apache-airflow-providers-fab` before 3.7.3. Users are advised to upgrade to `apache [truncated]

CRITICAL Apache Software Foundation CVE published 2026-07-29

CVE-2026-58179

The Apache Traffic Server regex_remap plugin has a stack overflow and integer overflow vulnerability from substitution input. This issue affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The vulnerability has a CVSS score of 9.2 and is classified as CRITICAL. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The op [truncated]

HIGH Apache Software Foundation CVE published 2026-07-29

CVE-2026-50622

A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations. This issue affects Apache Atlas versions from 0.8 through 2.5.0. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. Users are recommended to upgrade to version 2.6.0, which fixes the issue. The CVE record was [truncated]

HIGH Apache Software Foundation CVE published 2026-07-29

CVE-2026-58151

Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability allows for a crash or resource exhaustion through abusive HTTP/2 frami [truncated]

MEDIUM Apache Software Foundation CVE published 2026-07-29

CVE-2026-22068

The CVE-2026-22068 record indicates a Regular Expression without Anchors vulnerability in Apache Traffic Server versions from 10.0.X through 10.1.3 and from 9.0.X through 9.2.14. This issue allows attackers to potentially bypass security checks, leading to security risks. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. The CVSS score is 6.9 and the severity is MEDIUM. [truncated]

CRITICAL Apache Software Foundation CVE published 2026-07-28

CVE-2026-66713

CVE-2026-66713 is a deserialization of untrusted data vulnerability in the Tribes-based clustering component of Apache Axis2/Java. This vulnerability allows an unauthenticated remote attacker to execute arbitrary code via a crafted serialized Java object when Tribes clustering is enabled. The issue is resolved in version 2.0.1 by removing the clustering feature entirely. Affected deployments should be ide [truncated]

MEDIUM Apache Software Foundation CVE published 2026-07-28

CVE-2026-61487

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T14:16:38.453Z and has not been modified since then. This Improper Authorization vulnerability in Apache ActiveMQ allows an authenticated low-privilege user to bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physical name is a comma-separated comp [truncated]