These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
Apache OFBiz contains a reflected cross-site scripting (XSS) vulnerability due to improper neutralization of input during web page generation. The flaw affects all versions prior to 24.09.06. An attacker can exploit this by crafting a malicious URL that, when visited by an authenticated or unauthenticated user, executes arbitrary JavaScript in the victim's browser context. The CVSS 3.1 vector (AV:N/AC:L/P [truncated]
Apache OFBiz versions prior to 24.09.06 contain an Improper Access Control vulnerability (CWE-284) affecting multi-tenant deployments. The vulnerability, published 2026-05-19, allows unauthorized access with a CVSS 3.1 score of 5.3 (Medium severity). The attack vector is network-based with low attack complexity, requiring no privileges or user interaction. Apache has released version 24.09.06 to remediate [truncated]
CVE-2026-31380 is an Expression Language Injection issue in Apache OFBiz affecting versions before 24.09.06. The supplied advisory guidance recommends upgrading to 24.09.06, which fixes the flaw. Because expression-language weaknesses can allow attacker-controlled input to be interpreted in server-side expression contexts, this should be treated as a priority security update for affected deployments.
Apache OFBiz versions prior to 24.09.06 contain multiple vulnerability classes: Cross-site Scripting (CWE-79), Path Traversal (CWE-22), and Code Injection (CWE-94). The vendor published advisory details on 2026-05-19. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) indicates network attack vector, low attack complexity, no privileges required, user interaction required, scope change, with low im [truncated]
Apache OFBiz versions prior to 24.09.06 contain an improper neutralization of special elements used in a template engine (CWE-1336), allowing attackers to inject malicious content into FreeMarker templates. The vulnerability stems from insufficient sanitization of user-supplied input processed by the template engine, potentially enabling remote code execution or information disclosure depending on the app [truncated]
Apache Flink versions 1.15.0 through 1.20.x and 2.0.0 through 2.x contain a code injection vulnerability in SQL code generation. Authenticated users with query submission privileges can execute arbitrary code on TaskManagers by submitting maliciously crafted SQL queries. The vulnerability stems from improper escaping of user-controlled strings interpolated into generated Java code, affecting JSON function [truncated]
CVE-2026-42440 is a high-severity vulnerability in Apache OpenNLP's AbstractModelReader, which can lead to an Out-of-Memory (OOM) denial-of-service attack via unbounded array allocation. The vulnerability affects versions before 1.9.5, 2.5.9, and 3.0.0-M3. An attacker can craft a malicious .bin model file to trigger an OutOfMemoryError, causing the JVM to crash. The practical impact is a denial-of-service [truncated]
The CVE-2026-42027 vulnerability in Apache OpenNLP allows for arbitrary class instantiation via model manifest, potentially leading to security risks. Users should upgrade to version 2.5.9 or 3.0.0-M3 to mitigate the issue. This vulnerability exists due to the insecure use of Class.forName() and instantiation of classes from user-supplied model archives. Affected deployments should prioritize upgrading to [truncated]
CVE-2026-40682 is a critical vulnerability in Apache OpenNLP's DictionaryEntryPersistor class. The class initializes a static SAXParserFactory without enabling FEATURE_SECURE_PROCESSING or disabling DTD processing, allowing for XML External Entity (XXE) attacks via crafted dictionary files. This vulnerability affects versions before 2.5.9 and before 3.0.0-M3. An attacker can exploit this vulnerability to [truncated]
CVE-2026-33454 is a critical vulnerability in Apache Camel's Camel-Mail component. The custom header filter strategy used by the component only filters the 'out' direction, leaving the 'in' direction unfiltered. This allows an attacker to inject Camel-specific headers, potentially altering the behavior of downstream Camel components. The vulnerability affects Apache Camel versions from 3.0.0 before 4.14.6 [truncated]
CVE-2026-40453 is a critical vulnerability in Apache Camel that allows remote code execution and arbitrary file write. The vulnerability is caused by a case-insensitive header filtering issue in non-HTTP HeaderFilterStrategy implementations. An attacker with JMS producer access can inject case-variant Camel internal headers, which are then resolved by downstream components. This issue affects Apache Camel [truncated]
CVE-2026-41044 is a critical vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All. The vulnerability is caused by improper input validation and code injection, allowing an authenticated attacker to construct a malicious broker name that bypasses name validation. This can lead to arbitrary code execution on the broker's JVM. The vulnerability affects Apache ActiveMQ versions be [truncated]
CVE-2025-62233: Apache DolphinScheduler Deserialization of Untrusted Data Vulnerability allows attackers to compromise the system by creating a StandardRpcRequest and injecting a malicious class type. This issue affects Apache DolphinScheduler versions >= 3.2.0 and < 3.3.1. Defenders should assess exposure and prioritize upgrading to version 3.3.1 or later. The vulnerability enables attackers to inject ma [truncated]
CVE-2026-40542 is a high-severity vulnerability in Apache HttpClient 5.6 that allows an attacker to bypass proper mutual authentication verification for SCRAM-SHA-256 authentication. This vulnerability was published on April 22, 2026, and modified on June 30, 2026. The CVSS score for this vulnerability is 7.3, indicating a high severity. Users are recommended to upgrade to version 5.6.1, which fixes this [truncated]
Apache Doris MCP Server versions before 0.6.1 have an improper neutralization flaw in query context handling. This flaw may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP query execution interface. Version 0.6.1 and later are not affected. The vulnerability impacts defenders responsible for Apache Doris MCP Server deployments, w [truncated]
CVE-2026-39304 is a high-severity vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, and Apache ActiveMQ. The vulnerability is caused by the NIO SSL transports not correctly handling TLSv1.3 handshake KeyUpdates triggered by clients, leading to a Denial of Service (DoS) via Out of Memory. This issue affects Apache ActiveMQ Client, Apache ActiveMQ Broker, and Apache ActiveMQ versions before 5 [truncated]
CVE-2025-62188 debrief based on the supplied source corpus. An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler versions 3.1.*. This vulnerability may allow unauthorized actors to access sensitive information, including database credentials. Defenders responsible for Apache DolphinScheduler deployments should assess exposure and prioritize upgradin [truncated]
CVE-2026-25604 is a medium-severity vulnerability in Apache Airflow Providers Amazon, affecting versions prior to 9.22.0. The issue arises from the AWS Auth manager's failure to verify the origin of the SAML authentication response, allowing attackers to reuse SAML responses from other instances with potentially different access controls. This could lead to unauthorized access across different instances. [truncated]
CVE-2026-24281 is a high-severity vulnerability in Apache ZooKeeper, a popular coordination and configuration management system for distributed applications. The vulnerability arises from the way ZooKeeper's ZKTrustManager handles hostname verification. When IP SAN validation fails, it falls back to reverse DNS (PTR) lookup, which can be exploited by attackers who control or spoof PTR records. This allows [truncated]
CVE-2025-68280 Improper Restriction of XML External Entity Reference vulnerability in Apache SIS allows an attacker to reveal the content of a local file on the server by parsing a specially crafted XML file. This affects Apache SIS versions 0.4 through 1.5. Users should upgrade to version 1.6 or apply a workaround by setting the javax.xml.accessExternalDTD system property.
A Use After Free vulnerability in Apache NuttX RTOS' fs/vfs/fs_rename code allows for arbitrary user-provided size buffer reallocation and write to a previously freed heap chunk. This issue affects Apache NuttX RTOS versions from 7.20 to before 12.11.0 and could cause unintended virtual filesystem rename/move operation results, particularly for users of virtual filesystem-based services with write access [truncated]
CVE-2025-48768 is a Release of Invalid Pointer or Reference vulnerability in Apache NuttX RTOS, affecting versions from 10.0.0 before 12.10.0. The vulnerability allows root filesystem inode removal, potentially leading to a debug assert trigger, NULL pointer dereference, or Denial of Service. Users of filesystem-based services with write access exposed over the network, such as FTP, are affected and recom [truncated]
A vulnerability in Apache StreamPipes allows a non-administrator user to swap usernames with an administrator by exploiting the user ID creation mechanism. This can lead to administrative control, data tampering, and unauthorized access. The issue affects Apache StreamPipes through version 0.97.0 and is fixed in version 0.98.0. Users should assess exposure and upgrade to version 0.98.0 to fix the issue. T [truncated]
ABB’s ARM600 M2M Gateway is affected by CVE-2022-25147, an Apache Portable Runtime utility flaw in the base64 family of functions. The issue can trigger an out-of-bounds write when a very long string is encoded or decoded, which may allow data modification or denial of service. CISA’s advisory was published on 2025-04-07 and lists affected ABB M2M Gateway ARM600 firmware versions 4.1.2 through 5.0.3 and A [truncated]
CVE-2023-31122 is a high-severity availability issue affecting Hitachi Energy Service Suite versions 9.8.1.3 and below. The CISA advisory describes the underlying problem as Apache HTTP Server 2.4 vulnerabilities, with a CVSS 3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. Hitachi Energy’s remediation is to update Service Suite to version 9.8.1.4.
CVE-2022-28615 affects Hitachi Energy Service Suite versions 9.8.1.3 and below. CISA’s advisory describes the issue as Apache HTTP Server 2.4 vulnerabilities and assigns a CVSS v3.1 score of 9.1 (Critical). Hitachi Energy’s remediation is to update to version 9.8.1.4.
CVE-2024-27316 is a HIGH severity (CVSS 7.5) denial-of-service vulnerability affecting Siemens SINEC NMS. The issue stems from the nghttp2 HTTP/2 library's handling of incoming headers that exceed configured limits. When excessive headers are received, nghttp2 temporarily buffers them to generate an HTTP 413 (Payload Too Large) response. A malicious client can exploit this behavior by continuously sending [truncated]
CVE-2024-24795 is a MEDIUM-severity HTTP Response Splitting vulnerability affecting Apache HTTP Server, published on 2024-11-12. The vulnerability allows an attacker who can inject malicious response headers into backend applications to cause HTTP desynchronization attacks. Siemens SINEC NMS is affected as it incorporates the vulnerable Apache HTTP Server component. CISA published advisory ICSA-24-319-04 [truncated]
CVE-2023-38709 is a medium-severity HTTP response splitting vulnerability in Apache HTTP Server, affecting versions through 2.4.58. The flaw stems from faulty input validation in Apache's core, allowing malicious or exploitable backend/content generators to split HTTP responses. This vulnerability was published on November 12, 2024, with a CVSS 3.1 score of 6.1 (MEDIUM). Siemens SINEC NMS is identified as [truncated]
CVE-2022-23307 covers an insecure deserialization issue tied to Apache Chainsaw and, before Chainsaw 2.0, the Chainsaw component shipped with Apache Log4j 1.2.x. NVD scores it High (8.8) and lists affected Apache, reload4j, and multiple Oracle product CPEs, so the practical risk is broader than a standalone Apache installation.