PatchSiren

Apache Software Foundation CVE debriefs · Page 11

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Apache Software Foundation CVE published 2026-05-19

CVE-2026-31906

Apache OFBiz contains a reflected cross-site scripting (XSS) vulnerability due to improper neutralization of input during web page generation. The flaw affects all versions prior to 24.09.06. An attacker can exploit this by crafting a malicious URL that, when visited by an authenticated or unauthenticated user, executes arbitrary JavaScript in the victim's browser context. The CVSS 3.1 vector (AV:N/AC:L/P [truncated]

MEDIUM Apache Software Foundation CVE published 2026-05-19

CVE-2026-31388

Apache OFBiz versions prior to 24.09.06 contain an Improper Access Control vulnerability (CWE-284) affecting multi-tenant deployments. The vulnerability, published 2026-05-19, allows unauthorized access with a CVSS 3.1 score of 5.3 (Medium severity). The attack vector is network-based with low attack complexity, requiring no privileges or user interaction. Apache has released version 24.09.06 to remediate [truncated]

MEDIUM Apache Software Foundation CVE published 2026-05-19

CVE-2026-31380

CVE-2026-31380 is an Expression Language Injection issue in Apache OFBiz affecting versions before 24.09.06. The supplied advisory guidance recommends upgrading to 24.09.06, which fixes the flaw. Because expression-language weaknesses can allow attacker-controlled input to be interpreted in server-side expression contexts, this should be treated as a priority security update for affected deployments.

MEDIUM Apache Software Foundation CVE published 2026-05-19

CVE-2026-31379

Apache OFBiz versions prior to 24.09.06 contain multiple vulnerability classes: Cross-site Scripting (CWE-79), Path Traversal (CWE-22), and Code Injection (CWE-94). The vendor published advisory details on 2026-05-19. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) indicates network attack vector, low attack complexity, no privileges required, user interaction required, scope change, with low im [truncated]

MEDIUM Apache Software Foundation CVE published 2026-05-19

CVE-2026-29207

Apache OFBiz versions prior to 24.09.06 contain an improper neutralization of special elements used in a template engine (CWE-1336), allowing attackers to inject malicious content into FreeMarker templates. The vulnerability stems from insufficient sanitization of user-supplied input processed by the template engine, potentially enabling remote code execution or information disclosure depending on the app [truncated]

HIGH Apache Software Foundation CVE published 2026-05-15

CVE-2026-35194

Apache Flink versions 1.15.0 through 1.20.x and 2.0.0 through 2.x contain a code injection vulnerability in SQL code generation. Authenticated users with query submission privileges can execute arbitrary code on TaskManagers by submitting maliciously crafted SQL queries. The vulnerability stems from improper escaping of user-controlled strings interpolated into generated Java code, affecting JSON function [truncated]

HIGH Apache Software Foundation CVE published 2026-05-04

CVE-2026-42440

CVE-2026-42440 is a high-severity vulnerability in Apache OpenNLP's AbstractModelReader, which can lead to an Out-of-Memory (OOM) denial-of-service attack via unbounded array allocation. The vulnerability affects versions before 1.9.5, 2.5.9, and 3.0.0-M3. An attacker can craft a malicious .bin model file to trigger an OutOfMemoryError, causing the JVM to crash. The practical impact is a denial-of-service [truncated]

CRITICAL Apache Software Foundation CVE published 2026-05-04

CVE-2026-42027

The CVE-2026-42027 vulnerability in Apache OpenNLP allows for arbitrary class instantiation via model manifest, potentially leading to security risks. Users should upgrade to version 2.5.9 or 3.0.0-M3 to mitigate the issue. This vulnerability exists due to the insecure use of Class.forName() and instantiation of classes from user-supplied model archives. Affected deployments should prioritize upgrading to [truncated]

CRITICAL Apache Software Foundation CVE published 2026-05-04

CVE-2026-40682

CVE-2026-40682 is a critical vulnerability in Apache OpenNLP's DictionaryEntryPersistor class. The class initializes a static SAXParserFactory without enabling FEATURE_SECURE_PROCESSING or disabling DTD processing, allowing for XML External Entity (XXE) attacks via crafted dictionary files. This vulnerability affects versions before 2.5.9 and before 3.0.0-M3. An attacker can exploit this vulnerability to [truncated]

CRITICAL Apache Software Foundation CVE published 2026-04-27

CVE-2026-33454

CVE-2026-33454 is a critical vulnerability in Apache Camel's Camel-Mail component. The custom header filter strategy used by the component only filters the 'out' direction, leaving the 'in' direction unfiltered. This allows an attacker to inject Camel-specific headers, potentially altering the behavior of downstream Camel components. The vulnerability affects Apache Camel versions from 3.0.0 before 4.14.6 [truncated]

CRITICAL Apache Software Foundation CVE published 2026-04-27

CVE-2026-40453

CVE-2026-40453 is a critical vulnerability in Apache Camel that allows remote code execution and arbitrary file write. The vulnerability is caused by a case-insensitive header filtering issue in non-HTTP HeaderFilterStrategy implementations. An attacker with JMS producer access can inject case-variant Camel internal headers, which are then resolved by downstream components. This issue affects Apache Camel [truncated]

HIGH Apache Software Foundation CVE published 2026-04-24

CVE-2026-41044

CVE-2026-41044 is a critical vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All. The vulnerability is caused by improper input validation and code injection, allowing an authenticated attacker to construct a malicious broker name that bypasses name validation. This can lead to arbitrary code execution on the broker's JVM. The vulnerability affects Apache ActiveMQ versions be [truncated]

MEDIUM Apache Software Foundation CVE published 2026-04-24

CVE-2025-62233

CVE-2025-62233: Apache DolphinScheduler Deserialization of Untrusted Data Vulnerability allows attackers to compromise the system by creating a StandardRpcRequest and injecting a malicious class type. This issue affects Apache DolphinScheduler versions >= 3.2.0 and < 3.3.1. Defenders should assess exposure and prioritize upgrading to version 3.3.1 or later. The vulnerability enables attackers to inject ma [truncated]

HIGH Apache Software Foundation CVE published 2026-04-22

CVE-2026-40542

CVE-2026-40542 is a high-severity vulnerability in Apache HttpClient 5.6 that allows an attacker to bypass proper mutual authentication verification for SCRAM-SHA-256 authentication. This vulnerability was published on April 22, 2026, and modified on June 30, 2026. The CVSS score for this vulnerability is 7.3, indicating a high severity. Users are recommended to upgrade to version 5.6.1, which fixes this [truncated]

MEDIUM Apache Software Foundation CVE published 2026-04-20

CVE-2025-66335

Apache Doris MCP Server versions before 0.6.1 have an improper neutralization flaw in query context handling. This flaw may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP query execution interface. Version 0.6.1 and later are not affected. The vulnerability impacts defenders responsible for Apache Doris MCP Server deployments, w [truncated]

HIGH Apache Software Foundation CVE published 2026-04-10

CVE-2026-39304

CVE-2026-39304 is a high-severity vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, and Apache ActiveMQ. The vulnerability is caused by the NIO SSL transports not correctly handling TLSv1.3 handshake KeyUpdates triggered by clients, leading to a Denial of Service (DoS) via Out of Memory. This issue affects Apache ActiveMQ Client, Apache ActiveMQ Broker, and Apache ActiveMQ versions before 5 [truncated]

HIGH Apache Software Foundation CVE published 2026-04-09

CVE-2025-62188

CVE-2025-62188 debrief based on the supplied source corpus. An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler versions 3.1.*. This vulnerability may allow unauthorized actors to access sensitive information, including database credentials. Defenders responsible for Apache DolphinScheduler deployments should assess exposure and prioritize upgradin [truncated]

MEDIUM Apache Software Foundation CVE published 2026-03-09

CVE-2026-25604

CVE-2026-25604 is a medium-severity vulnerability in Apache Airflow Providers Amazon, affecting versions prior to 9.22.0. The issue arises from the AWS Auth manager's failure to verify the origin of the SAML authentication response, allowing attackers to reuse SAML responses from other instances with potentially different access controls. This could lead to unauthorized access across different instances. [truncated]

HIGH Apache Software Foundation CVE published 2026-03-07

CVE-2026-24281

CVE-2026-24281 is a high-severity vulnerability in Apache ZooKeeper, a popular coordination and configuration management system for distributed applications. The vulnerability arises from the way ZooKeeper's ZKTrustManager handles hostname verification. When IP SAN validation fails, it falls back to reverse DNS (PTR) lookup, which can be exploited by attackers who control or spoof PTR records. This allows [truncated]

MEDIUM Apache Software Foundation CVE published 2026-01-05

CVE-2025-68280

CVE-2025-68280 Improper Restriction of XML External Entity Reference vulnerability in Apache SIS allows an attacker to reveal the content of a local file on the server by parsing a specially crafted XML file. This affects Apache SIS versions 0.4 through 1.5. Users should upgrade to version 1.6 or apply a workaround by setting the javax.xml.accessExternalDTD system property.

HIGH Apache Software Foundation CVE published 2026-01-01

CVE-2025-48769

A Use After Free vulnerability in Apache NuttX RTOS' fs/vfs/fs_rename code allows for arbitrary user-provided size buffer reallocation and write to a previously freed heap chunk. This issue affects Apache NuttX RTOS versions from 7.20 to before 12.11.0 and could cause unintended virtual filesystem rename/move operation results, particularly for users of virtual filesystem-based services with write access [truncated]

MEDIUM Apache Software Foundation CVE published 2026-01-01

CVE-2025-48768

CVE-2025-48768 is a Release of Invalid Pointer or Reference vulnerability in Apache NuttX RTOS, affecting versions from 10.0.0 before 12.10.0. The vulnerability allows root filesystem inode removal, potentially leading to a debug assert trigger, NULL pointer dereference, or Denial of Service. Users of filesystem-based services with write access exposed over the network, such as FTP, are affected and recom [truncated]

HIGH Apache Software Foundation CVE published 2026-01-01

CVE-2025-47411

A vulnerability in Apache StreamPipes allows a non-administrator user to swap usernames with an administrator by exploiting the user ID creation mechanism. This can lead to administrative control, data tampering, and unauthorized access. The issue affects Apache StreamPipes through version 0.97.0 and is fixed in version 0.98.0. Users should assess exposure and upgrade to version 0.98.0 to fix the issue. T [truncated]

MEDIUM Apache Software Foundation CVE published 2025-04-07

CVE-2022-25147

ABB’s ARM600 M2M Gateway is affected by CVE-2022-25147, an Apache Portable Runtime utility flaw in the base64 family of functions. The issue can trigger an out-of-bounds write when a very long string is encoded or decoded, which may allow data modification or denial of service. CISA’s advisory was published on 2025-04-07 and lists affected ABB M2M Gateway ARM600 firmware versions 4.1.2 through 5.0.3 and A [truncated]

HIGH Apache Software Foundation CVE published 2025-02-25

CVE-2023-31122

CVE-2023-31122 is a high-severity availability issue affecting Hitachi Energy Service Suite versions 9.8.1.3 and below. The CISA advisory describes the underlying problem as Apache HTTP Server 2.4 vulnerabilities, with a CVSS 3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. Hitachi Energy’s remediation is to update Service Suite to version 9.8.1.4.

CRITICAL Apache Software Foundation CVE published 2025-02-25

CVE-2022-28615

CVE-2022-28615 affects Hitachi Energy Service Suite versions 9.8.1.3 and below. CISA’s advisory describes the issue as Apache HTTP Server 2.4 vulnerabilities and assigns a CVSS v3.1 score of 9.1 (Critical). Hitachi Energy’s remediation is to update to version 9.8.1.4.

HIGH Apache Software Foundation CVE published 2024-11-12

CVE-2024-27316

CVE-2024-27316 is a HIGH severity (CVSS 7.5) denial-of-service vulnerability affecting Siemens SINEC NMS. The issue stems from the nghttp2 HTTP/2 library's handling of incoming headers that exceed configured limits. When excessive headers are received, nghttp2 temporarily buffers them to generate an HTTP 413 (Payload Too Large) response. A malicious client can exploit this behavior by continuously sending [truncated]

MEDIUM Apache Software Foundation CVE published 2024-11-12

CVE-2024-24795

CVE-2024-24795 is a MEDIUM-severity HTTP Response Splitting vulnerability affecting Apache HTTP Server, published on 2024-11-12. The vulnerability allows an attacker who can inject malicious response headers into backend applications to cause HTTP desynchronization attacks. Siemens SINEC NMS is affected as it incorporates the vulnerable Apache HTTP Server component. CISA published advisory ICSA-24-319-04 [truncated]

MEDIUM Apache Software Foundation CVE published 2024-11-12

CVE-2023-38709

CVE-2023-38709 is a medium-severity HTTP response splitting vulnerability in Apache HTTP Server, affecting versions through 2.4.58. The flaw stems from faulty input validation in Apache's core, allowing malicious or exploitable backend/content generators to split HTTP responses. This vulnerability was published on November 12, 2024, with a CVSS 3.1 score of 6.1 (MEDIUM). Siemens SINEC NMS is identified as [truncated]

HIGH Apache Software Foundation CVE published 2022-01-18

CVE-2022-23307

CVE-2022-23307 covers an insecure deserialization issue tied to Apache Chainsaw and, before Chainsaw 2.0, the Chainsaw component shipped with Apache Log4j 1.2.x. NVD scores it High (8.8) and lists affected Apache, reload4j, and multiple Oracle product CPEs, so the practical risk is broader than a standalone Apache installation.