These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
An executive overview of CVE-2026-73635: Apache Struts users should be aware of an allocation of resources without limits or throttling vulnerability. This vulnerability can cause the framework's internal localized-text caches to grow without bound and exhaust the Java heap, denying service to other users. The CVE record was published on 2026-08-15T11:16:27.540Z and has not been modified since then. Affec [truncated]
The CVE-2026-73634 record describes an uncontrolled resource consumption vulnerability in Apache Struts, affecting versions from 6.0.0 through 6.10.0 and from 7.0.0 through 7.2.1. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, allowing a single request to exhaust the heap and deny [truncated]
A vulnerability exists in Apache Tapestry 5.5.0+ on all platforms, allowing attackers to download classpath assets via specially crafted URLs. This issue poses a significant risk to users of Apache Tapestry 5.5.0+ as it could potentially lead to unauthorized access to sensitive data. Users are recommended to upgrade to version 5.9.1, which fixes this issue. It is crucial for operators, platform administra [truncated]
CVE-2026-55814 is a missing authentication issue in Apache Ranger Download APIs versions <= 2.8.0. This vulnerability allows unauthorized access to download APIs, potentially impacting system security and data integrity. Apache Ranger users and administrators should verify their systems for potential exposure and review system configurations. The issue has not been modified since its publication on 2026-0 [truncated]
CVE-2026-44416 is a Remote Code Execution vulnerability via Arbitrary Class Instantiation in the plugin-schema-registry component of Apache Ranger versions <= 2.8.0. This vulnerability allows attackers to execute arbitrary code, potentially leading to a complete compromise of the affected system. The CVE record was published on 2026-08-10T11:17:26.547Z and has not been modified since then. However, the fu [truncated]
CVE-2026-42537 is a Remote Code Execution vulnerability via JDBC URL Injection in Apache Ranger versions <= 2.8.0. The issue is addressed in version 2.9.0. Apache Ranger users should prioritize upgrading to version 2.9.0 and review JDBC URL configurations to prevent exploitation. Limited evidence suggests Apache Ranger users should verify affected deployments, review compensating controls, and monitor for [truncated]
Apache IoTDB RPC service vulnerability allows remote unauthenticated attackers to cause denial of service via crafted Thrift frame. Affected versions: Apache IoTDB before 1.3.8, 2.0.0 to 2.0.9. Upgrade to 2.0.10 to fix. The vulnerability is caused by improper validation of length fields in the Apache IoTDB RPC service, which can lead to excessive memory allocation and a crash with an OutOfMemoryError. Sec [truncated]
CVE-2026-34502 is a heap-based buffer overflow vulnerability in the Apache Portable Runtime Utility (APR-Util) memcached client, affecting versions from 1.3.0 through 1.6.3. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. The CWE associated with this vulnerability is CWE-122. The vulnerability can be exploited by sending a specially crafted request to the memcached client, po [truncated]
The CVE record for CVE-2026-34191 was published on 2026-08-06T15:16:54.650Z and has not been modified since then. The NVD entry is currently Analyzed. This SQL injection vulnerability in Apache Portable Runtime Utility has a critical CVSS score of 9.1 and requires immediate attention. Organizations using affected versions should prioritize patching to prevent potential SQL injection attacks. The vulnerabi [truncated]
Apache CXF's DefaultEncryptingOAuthDataProvider incorrectly handles revoked access and refresh tokens, allowing them to decrypt successfully and be reported as active by TokenIntrospectionService, contrary to RFC requirements. This vulnerability affects users of Apache CXF, particularly those using DefaultEncryptingOAuthDataProvider for token management. The issue involves improper invalidation of revoked [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T12:16:28.060Z and has not been modified since then. Apache CXF's DefaultEncryptingCodeDataProvider has a flaw in the implementation of the removeCodeGrant functionality, allowing a captured authorization code to be redeemed an unlimited number of times. This violates the RFC requirement that 'The [truncated]
Apache CXF's OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, self-issued ID tokens are not accepted by default in the validator. The vulnerability's technical impact is significant, as it allows for potential authentication bypass. [truncated]
Apache CXF's JwtRequestCodeFilter vulnerability allows a client with a validly-signed request JWT to substitute sensitive values, undermining PKCE integrity and OpenID Connect replay protection. Affected product deployments should be reviewed for potential security risks. The CVE record was published on 2026-08-06T12:16:27.843Z and has not been modified since then. This issue affects Apache CXF users, sec [truncated]
Apache CXF's OAuth2 Dynamic Client Registration endpoint is vulnerable due to lack of validation against an AS-defined allowlist, potentially allowing scope elevation. Affected product deployments should be identified and reviewed for exposure. The CVE record was published on 2026-08-06T12:16:27.730Z. Users should review the official advisory and plan vendor-supported updates or mitigations.
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserial [truncated]
Apache CXF is vulnerable to XML External Entity (XXE) attacks due to improper handling of imported WSDL/XSD content. The vulnerability exists because while the top-level WSDL is processed with protections against XML DTDs and external entities, any imported documents are handled by WSDL4J without these protections. This issue affects users of Apache CXF, especially those using versions prior to 3.6.12, 4. [truncated]
Apache CXF OpenID Connect Hybrid Flow vulnerability. The OpenID Connect Core 1.0 specification requires validation of the `c_hash` parameter in Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP is vulnerable to Authorization Code Substitution/Injection attacks. Users should upgrade to versions 4.2.3, 4.1.8, or 3.6.12.
The CVE-2026-54225 vulnerability affects Apache CXF, a popular open-source services framework. This denial of service vulnerability arises from the lack of a default limit on attachment size, allowing attackers to perform denial of service attacks if users don't explicitly set a limit. The update introduces a default attachment size limit of 50mb in Apache CXF versions 4.2.3, 4.1.8, and 3.6.12. Users of A [truncated]
Insufficient Session Expiration vulnerability in Apache Answer allows continued access with Administrative API keys after administrator demotion or account inactivation until keys are explicitly removed. This issue affects Apache Answer versions through 2.0.1, posing a medium risk to administrators and users who have not upgraded to version 2.0.2. The vulnerability enables unauthorized access due to the l [truncated]
The CVE-2026-60023 vulnerability in Apache Answer through version 2.0.1 allows unauthorized users to retrieve deleted or pending answers when the parent question remains visible. This Exposure of Sensitive Information vulnerability can have significant operational impacts if not properly mitigated. Affected users should upgrade to version 2.0.2 to prevent unauthorized access to sensitive information. This [truncated]
The CVE-2026-48911 vulnerability is an Insufficient Verification of Data Authenticity issue in Apache Answer through version 2.0.1. A missing authorization check in the external-login email binding flow allows unauthenticated attackers to take over arbitrary user accounts by tricking victims into clicking a crafted confirmation link. This issue affects Apache Answer through version 2.0.1, and users are re [truncated]
The CVE-2026-48834 record describes an Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer through version 2.0.1. This allows unauthenticated attackers to cause a denial of service via a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing. Organizations should review their deployments and consider upgrading to mitigate potential impacts.
This PatchSiren debrief is based on the supplied source corpus for CVE-2026-61485, which describes a Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. The CVE record was published on 2026-08-05T08:16:35.610Z and has not been modified since then. The NVD entry is currently empty. Organizations using Apache Lucy or its components should be aware of this vulnerability. Given that the [truncated]
CVE-2026-61483 is an Uncontrolled Recursion vulnerability in Apache Lucy, affecting all versions. The project is retired, and no fix is planned. Users of Apache Lucy should be aware of the vulnerability and take necessary actions to protect their systems. This includes assessing usage, considering migration, and restricting access if needed. The CVE record was published on 2026-08-05T08:16:35.330Z and has [truncated]
An authenticated attacker could cause excessive resource usage and potential denial of service due to a lack of rate governance for echo flow responses from the broker. This issue affects Apache Qpid Broker-J through 10.0.1. Users are recommended to upgrade to version 10.1.0. The vulnerability can be mitigated by upgrading to version 10.1.0, which fixes the issue. The broker did not govern the rate at whi [truncated]
Apache Qpid Broker-J vulnerability CVE-2026-68078 allows authenticated attackers to cause excessive resource usage and potential denial of service due to lack of governance on the maximum number of transfer frames per incoming delivery. This issue affects Apache Qpid Broker-J through version 10.0.1, and users are recommended to upgrade to version 10.1.0. Operators, platform administrators, and security te [truncated]
An authenticated attacker could exceed the session flow control incoming window, potentially leading to denial of service. This issue affects Apache Qpid Broker-J through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue. The vulnerability is related to session flow control, and defenders should review Apache Qpid Broker-J deployments and plan upgrades.
The CVE-2026-67555 issue is a denial of service vulnerability in Apache Qpid Proton-Dotnet through 1.0.0. An authenticated attacker can cause excessive resource usage and potential denial of service by not governing the maximum number of transfer frames per incoming delivery. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. Users are recommended to upgrade to version 1.1.0. The CVE record was p [truncated]
CVE-2026-66277 was reported in Apache Qpid Proton-J, where an authenticated user could cause excessive resource usage and potential denial of service due to a lack of governance on the maximum number of transfer frames per incoming delivery. The issue affects Apache Qpid Proton-J through version 0.34.1. Users are recommended to upgrade to version 0.35.0. AI-assisted PatchSiren debrief based on the supplie [truncated]
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. The vulnerability can lead to a denial of service, potentially impacting system availability and requiri [truncated]
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service in Apache Qpid Broker-J through 10.0.1. This denial of service vulnerability can impact the availability of the system, potentially leading to service disruptions. Users are recommended to upgrade to version 10.1.0 to mitigate this issue. Additionally, defenders should [truncated]
A regression vulnerability in Apache Tomcat's EncryptInterceptor allows bypass of encryption protections for sensitive data in transit. The flaw was introduced by the fix for CVE-2026-29146, creating a missing encryption condition (CWE-311) that exposes confidential data to network adversaries. Affected versions are 9.0.116, 10.1.53, and 11.0.20. The vulnerability carries a HIGH severity CVSS 7.5 score wi [truncated]
The CVE-2026-68981 vulnerability affects Apache NiFi 1.5.0 through 2.10.0, allowing malicious clients to send crafted gzip-encoded HTTP requests that could consume excessive amounts of memory due to improper handling of decompressed payloads. Organizations should verify their deployments, review the official advisory and CVE record to validate affected scope, severity, and vendor guidance, and consider up [truncated]
Apache NiFi 2.0.0 through 2.10.0 has a vulnerability related to asset deletion authorization. The framework authorizes asset deletion against the owning Parameter Context using a supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. This issue can be mitigated by upgrading to Apache NiFi 2.11.0, which verifies Parameter Context ownership of the req [truncated]
Apache NiFi 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and write privileges on the Parameter Context itself. As a result of the missing authorizatio [truncated]
The CVE-2026-62391 record details an incomplete security fix for CVE-2025-66518, affecting Apache Kyuubi from version 1.6.0 to before 1.12.0. This allows clients to bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. Apache Kyuubi users and administrators should be aware of the potential security risks and take necessary actions to mitigate them.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T11:17:10.087Z and has not been modified since then. CVE-2026-44615 is a path traversal vulnerability in Apache Zeppelin's FileSystemNotebookRepo configuration. An authenticated attacker with permission to rename notes or access folder operations could supply traversal segments in note or folder p [truncated]
The CVE-2026-52680 vulnerability affects Apache Kyuubi, a software component used for data processing and management. The vulnerability class is related to path traversal in the REST batch multipart upload handling, allowing remote attackers to write controlled content outside the intended upload directory. The likely operational impact is high, as it can lead to arbitrary file writes, potentially allowin [truncated]
The CVE-2026-44617 record describes an LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm uses RFC 4514 distinguished-name escaping when constructing LDAP search filters instead of RFC 4515 filter escaping. This leaves special filter characters insufficiently escaped, allowing for potential attacks. The issue affects Apache Zeppelin versions 0.11.1, 0.11.2, and 0.12.0. Users are recommended [truncated]
The CVE-2026-44616 record indicates an LDAP injection vulnerability in Apache Zeppelin, specifically in the ActiveDirectoryGroupRealm when constructing LDAP search filters without escaping user-controlled input. This issue affects versions 0.6.0 through 0.12.0, and users are recommended to upgrade to version 0.12.1. The vulnerability allows an authenticated attacker to inject LDAP filter syntax through th [truncated]
Apache JSPWiki up to 2.12.3 is vulnerable to JSON Hijacking, leading to CSRF vulnerabilities. The vulnerability has a CVSS score of 8.8 and is classified as HIGH. Users are recommended to upgrade to version 2.12.4, which fixes this issue. However, the specific details of the vulnerability and its potential impact are not well understood at this time. Affected deployments should be identified and owners as [truncated]
Apache JSPWiki up to 2.12.3 has a UserManager impersonation vulnerability CVE-2026-28812, with a CVSS score of 9.8. This vulnerability allows attackers to escalate privileges due to a lack of checks in the UserManager. The affected product is Apache JSPWiki up to version 2.12.3, and the vulnerability class is impersonation. The likely operational impact is privilege escalation. The source-confidence limit [truncated]
The CVE-2026-28811 issue involves Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. This vulnerability allows attackers to access sensitive information through debug messages, potentially leading to information disclosure. The issue has a CVSS score of 7.5 and is classified as HIGH severity. Users are recommended to upgrade to version 2.12.4, which fixes this issue. Operator [truncated]
The CVE record for CVE-2026-59243 was published on 2026-07-29T10:16:44.390Z. The vulnerability affects the FAB auth manager's Azure AD OAuth login, which defaulted to `verify_signature=False` when decoding the ID token. This allowed an attacker to bypass authentication with a forged or unsigned ID token. The issue affects `apache-airflow-providers-fab` before 3.7.3. Users are advised to upgrade to `apache [truncated]
The Apache Traffic Server regex_remap plugin has a stack overflow and integer overflow vulnerability from substitution input. This issue affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The vulnerability has a CVSS score of 9.2 and is classified as CRITICAL. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The op [truncated]
A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations. This issue affects Apache Atlas versions from 0.8 through 2.5.0. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. Users are recommended to upgrade to version 2.6.0, which fixes the issue. The CVE record was [truncated]
Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. The vulnerability allows for a crash or resource exhaustion through abusive HTTP/2 frami [truncated]
The CVE-2026-22068 record indicates a Regular Expression without Anchors vulnerability in Apache Traffic Server versions from 10.0.X through 10.1.3 and from 9.0.X through 9.2.14. This issue allows attackers to potentially bypass security checks, leading to security risks. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. The CVSS score is 6.9 and the severity is MEDIUM. [truncated]
CVE-2026-66713 is a deserialization of untrusted data vulnerability in the Tribes-based clustering component of Apache Axis2/Java. This vulnerability allows an unauthenticated remote attacker to execute arbitrary code via a crafted serialized Java object when Tribes clustering is enabled. The issue is resolved in version 2.0.1 by removing the clustering feature entirely. Affected deployments should be ide [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T14:16:38.453Z and has not been modified since then. This Improper Authorization vulnerability in Apache ActiveMQ allows an authenticated low-privilege user to bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physical name is a comma-separated comp [truncated]