PatchSiren

Apache Software Foundation CVE debriefs · Page 10

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Apache Software Foundation CVE published 2026-06-01

CVE-2026-41084

A CWE-639 authorization bypass in Apache Airflow's bulk Task Instances API allows authenticated users with edit permission on one DAG to mutate Task Instance state in any other DAG. The vulnerability exists because the `PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstances` endpoint evaluates authorization against the `dag_id` in the URL path while applying mutations to `dag_id` and `dag_r [truncated]

MEDIUM Apache Software Foundation CVE published 2026-06-01

CVE-2026-41017

Apache Airflow's JWTRefreshMiddleware fails to set the Secure flag on JWT authentication cookies, exposing session tokens to cleartext transmission in deployments using TLS-terminating reverse proxies. When the Airflow API server sits behind an HTTPS-terminating proxy (nginx, Envoy, managed load balancers) that forwards plaintext HTTP to the backend, the middleware's omission of the Secure attribute cause [truncated]

MEDIUM Apache Software Foundation CVE published 2026-06-01

CVE-2026-41014

CVE-2026-41014 is an authorization bypass in Apache Airflow's partitioned_dag_runs endpoints, published 2026-06-01. The Airflow UI endpoints enforced only asset-level access control rather than per-DAG authorization. An authenticated UI/API user with global Asset:read permission could enumerate partition run state, schedule configuration, and asset wiring for DAGs they were not authorized to read. This af [truncated]

LOW Apache Software Foundation CVE published 2026-06-01

CVE-2026-40963

An authorization bypass in Apache Airflow's structure_data endpoint allows authenticated users to enumerate linked DAG IDs and dependency metadata for DAGs they lack read permission to access. The endpoint returns external dependency graph nodes without verifying read permissions on linked DAGs, undermining per-DAG access controls in multi-team deployments.

HIGH Apache Software Foundation CVE published 2026-06-01

CVE-2026-40961

A URL redirection vulnerability in Apache Airflow's login redirect route allows authenticated users to craft URLs that bypass the `is_safe_url` validation, enabling open redirect attacks from a trusted Airflow domain to attacker-controlled origins. The flaw resides in insufficient validation of the `next=` query parameter during login flow redirection. Apache has addressed this in version 3.2.2. The vulne [truncated]

MEDIUM Apache Software Foundation CVE published 2026-06-01

CVE-2026-40861

A path traversal vulnerability in Apache Airflow's FileTaskHandler allows DAG authors to read or overwrite arbitrary files accessible to the API server process. Two attack vectors exist: (a) a symlink placed under the task's log directory pointing to sensitive files like /etc/passwd or airflow.cfg (read-path), and (b) a task_id containing .. sequences that pass the Task SDK's KEY_REGEX validation (write-p [truncated]

MEDIUM Apache Software Foundation CVE published 2026-06-01

CVE-2026-45192

A vulnerability in Apache Airflow's GET /api/v2/connections/{connection_id} REST API endpoint allowed authenticated users with Connection-read permission to retrieve secrets stored in a Connection's extra JSON blob when those secrets were stored under field names not present in the default redaction allowlist (DEFAULT_SENSITIVE_FIELDS). The issue was disclosed on 2026-06-01 and affects deployments that st [truncated]

HIGH Apache Software Foundation CVE published 2026-06-01

CVE-2026-35563

An LDAP client implementation in version 2.1.7 fails to perform TLS endpoint identification (hostname verification), allowing a valid certificate for an unrelated host to be accepted if the certificate chain validates against a trusted authority. The vulnerability requires an attacker with network MITM capability who can present a certificate trusted by the client's configured trust store. The root cause [truncated]

MEDIUM Apache Software Foundation CVE published 2026-05-28

CVE-2026-40914

A vulnerability in Apache Artemis allows authenticated STOMP protocol users with consume or send permissions on an address to bypass routing-type restrictions. Specifically, such users can augment the routing-type supported by an address even without holding the createAddress permission, enabling message operations on routing-types that should be rejected. The issue stems from improper authorization check [truncated]

HIGH Apache Software Foundation CVE published 2026-05-28

CVE-2025-48977

Apache Ignite versions 2.0.0 through 2.17.0 contain a relative path traversal vulnerability (CWE-23) in the REST API. Authenticated attackers can exploit the `cmd=log` command with a specially crafted log path to read arbitrary files on the server. The vulnerability is rated HIGH severity with a CVSS score of 8.5. Apache has released version 2.18.0 to address this issue. The vulnerability was disclosed vi [truncated]

MEDIUM Apache Software Foundation CVE published 2026-05-26

CVE-2026-40564

Apache Flink Kubernetes Operator versions 1.3.0 through 1.14.x contain a vulnerability where the FlinkSessionJob jarURI parameter is not validated to ensure it points to user-owned files or addresses. This allows users with Custom Resource (CR) create permissions to read files from the operator pod's filesystem and pull content from any backing store reachable through Flink's pluggable filesystem layer. A [truncated]

NONE Apache Software Foundation CVE published 2026-05-25

CVE-2026-48589

Apache Shiro's Jakarta EE integration module contains an open redirect vulnerability due to insufficient validation of the HTTP Referer header when issuing post-login redirects. The vulnerability exists in the shiro-jakarta-ee module from versions 2.0-alpha through 2.2.0, and in version 3.0.0-alpha-1. The HTTP Referer header is client-controlled, and without proper validation, an attacker can influence th [truncated]

MEDIUM Apache Software Foundation CVE published 2026-05-25

CVE-2026-44598

Apache Shiro's Jakarta EE integration module (shiro-jakarta-ee) contains an open redirect and server-side request forgery (SSRF) vulnerability in the shiroSavedRequest cookie handling. After successful authentication, this cookie is used to redirect users to a post-login destination, but the cookie value is neither validated nor encrypted. An attacker with valid login credentials can forge the cookie to c [truncated]

MEDIUM Apache Software Foundation CVE published 2026-05-25

CVE-2026-43828

Apache Shiro versions 1.0 through 2.1.0 and 3.0.0-alpha-1 fail to set the 'Secure' attribute on sensitive session cookies (JSESSIONID) and Remember-Me cookies by default. When applications are deployed over HTTPS, this omission allows browsers to transmit these cookies over unencrypted HTTP connections if available, exposing session identifiers to potential interception. The vulnerability stems from defau [truncated]

MEDIUM Apache Software Foundation CVE published 2026-05-25

CVE-2026-43827

Apache Shiro versions 1.0 through 2.1.0 and 3.0.0-alpha-1 contain a session fixation vulnerability in default configurations. When a session already exists, it is not invalidated upon successful login, and no new session with a fresh ID is generated. This allows an attacker who obtains a pre-authentication session ID to potentially hijack the authenticated session. The vulnerability was published on 2026- [truncated]

MEDIUM Apache Software Foundation CVE published 2026-05-25

CVE-2026-42797

Apache Syncope versions 3.0 through 3.0.16, 4.0 through 4.0.5, and 4.1.0 contain an information disclosure vulnerability (CWE-202) in the Derived Schemas feature. An administrator with entitlements to create Derived Schemas can craft a malicious JEXL expression that, when evaluated during User read operations by another administrator, exposes security-sensitive user information. The vulnerability stems fr [truncated]

HIGH Apache Software Foundation CVE published 2026-05-25

CVE-2026-42782

Apache Syncope versions 3.0 through 3.0.16, 4.0 through 4.0.5, and 4.1.0 contain an improper isolation or compartmentalization vulnerability (CWE-653). An administrator with sufficient entitlements for Implementations can create a malicious Groovy class containing untrusted code that reaches a non-sandboxed execution path via the class static initializer. The vulnerability was published on 2026-05-25 and [truncated]

MEDIUM Apache Software Foundation CVE published 2026-05-25

CVE-2026-46745

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. The vulnerability was published on 2026-05-25 and last modified on 2026-05-26. The issue affects the Flask-AppBuilder (FAB) authentication manager component when LDAP authentication is enabled. Attackers can manipulate LDAP fi [truncated]

HIGH Apache Software Foundation CVE published 2026-05-25

CVE-2026-45361

Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. The vulnerability stems from the hook's default configuration that skips host-key verification, allowing man-in-the-middle attacks against SSH connections. This af [truncated]

MEDIUM Apache Software Foundation CVE published 2026-05-25

CVE-2026-45249

A stored cross-site scripting (XSS) vulnerability exists in Apache ECharts versions prior to 6.1.0, specifically within the Lines series tooltip rendering logic. The issue occurs when the Lines series is used with tooltips enabled, no custom tooltip.formatter is specified, and series.data[i].name contains attacker-controlled HTML. In this configuration, the built-in tooltip formatter fails to escape the n [truncated]

HIGH Apache Software Foundation CVE published 2026-05-22

CVE-2026-44417

CVE-2026-44417 is a high-severity vulnerability in Apache CXF, a popular open-source services framework. The issue arises from an incomplete fix for CVE-2025-48913, which allowed untrusted users to configure JMS for Apache CXF, potentially leading to remote code execution. The vulnerability has a CVSS score of 7.5 and is considered high-severity. Users are recommended to upgrade to versions 4.2.1, 4.1.6, [truncated]

CRITICAL Apache Software Foundation CVE published 2026-05-21

CVE-2026-48207

CVE-2026-48207 is a critical deserialization weakness in Apache Fory PyFory before 1.0.0. According to the Apache security notice and NVD, ReduceSerializer could bypass documented DeserializationPolicy validation during reduce-state restoration and global-name resolution, which matters when applications deserialize attacker-controlled data in Python-native mode with strict mode disabled.

HIGH Apache Software Foundation CVE published 2026-05-21

CVE-2026-45760

CVE-2026-45760 affects Apache Camel K and involves an authorization bypass through a user-controlled key / externally controlled reference issue. According to the published description, an authorized user in a Kubernetes namespace can create a Build resource and influence where the resulting Pod is generated, including in the operator namespace. Apache recommends upgrading to a fixed release: 2.8.1, 2.9.2 [truncated]

MEDIUM Apache Software Foundation CVE published 2026-05-19

CVE-2026-42526

CVE-2026-42526 is a confidentiality issue in the experimental multi-tenant teams feature of apache-airflow-providers-amazon. In the AWS Secrets Manager and SSM Parameter Store secrets backends, a team-scoping collision could let a privileged caller without team context retrieve another team's secret by choosing a conn_id that mapped to the same path. The issue was fixed in 9.28.0 by changing the separator [truncated]

HIGH Apache Software Foundation CVE published 2026-05-19

CVE-2026-27173

CVE-2026-27173 describes an information exposure issue affecting JWT tokens used by workers in Kubernetes Executors. According to the advisory text, users with read-only access to Kubernetes Pods could see those tokens and potentially use them to perform actions reserved for running tasks via Task SDK, with possible impact to Airflow task-related database state. The published CVSS 3.1 vector is AV:L/AC:L/ [truncated]

HIGH Apache Software Foundation CVE published 2026-05-19

CVE-2026-46586

CVE-2026-46586 is a high-severity Apache OFBiz issue affecting versions before 24.09.06. NVD rates it 8.8 (HIGH) with network attack vector, low attack complexity, and low privileges required. The vendor advisory recommends upgrading to 24.09.06, which fixes the issue.

MEDIUM Apache Software Foundation CVE published 2026-05-19

CVE-2026-45187

Apache OFBiz Webtools contains an improper authorization vulnerability (CWE-285) that could allow unauthorized access to administrative functionality. The vulnerability affects all versions prior to 24.09.06. Apache released version 24.09.06 on May 19, 2026 to address this issue. The CVSS 3.1 score of 6.5 (Medium) reflects network attack vector with low complexity, no required privileges or user interacti [truncated]

CRITICAL Apache Software Foundation CVE published 2026-05-19

CVE-2026-41919

Apache OFBiz versions prior to 24.09.06 contain a critical LDAP injection vulnerability (CWE-90) that allows unauthenticated remote attackers to manipulate LDAP queries. The vulnerability stems from improper neutralization of special elements in LDAP queries, potentially enabling authentication bypass, privilege escalation, or unauthorized data access in environments using LDAP for directory services. The [truncated]

CRITICAL Apache Software Foundation CVE published 2026-05-19

CVE-2026-31986

Apache OFBiz contains a use of hard-coded cryptographic key vulnerability (CWE-321) in versions prior to 24.09.06. The vulnerability carries a CVSS 3.1 score of 9.1 (Critical), with network attack vector, low attack complexity, no required privileges, and no user interaction needed. Successful exploitation could result in high impact to confidentiality and integrity. Apache released version 24.09.06 on Ma [truncated]

HIGH Apache Software Foundation CVE published 2026-05-19

CVE-2026-31910

CVE-2026-31910 is a server-side request forgery (SSRF) issue affecting Apache OFBiz versions before 24.09.06. The vendor guidance in the CVE description recommends upgrading to 24.09.06, which fixes the issue.