These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-92609 debrief: Apache Qpid Broker-J session fixation vulnerability allows unauthorized access. Users should upgrade to version 10.1.1. This issue affects Apache Qpid Broker-J through 10.1.0, enabling remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. Defenders should assess exposure and p [truncated]
CVE-2026-92608 debrief: Apache Qpid Broker-J is vulnerable to disruption via improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion, affecting versions through 10.1.0. This issue allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers. Defenders and administrators should verify affected versions, upgrade to version 10.1.1, and monitor for po [truncated]
CVE-2026-97636 debrief: Apache Airflow HashiCorp provider vulnerability allows bypassing team-scope guard, potentially leading to unauthorized access in multi-team deployments using HashiCorp Vault secrets backend. Affected deployments should verify and update to version 4.8.0 or later. This vulnerability is similar to CVE-2026-86465, CVE-2026-68870, CVE-2026-68871, and CVE-2026-68872 in other secrets bac [truncated]
CVE-2026-86473 debrief: Apache Airflow Core API logout endpoint fails to revoke session tokens presented as Authorization bearer headers, allowing an attacker with a valid token to maintain access after a victim logs out. This issue affects API clients that authenticate with a bearer token rather than the browser session cookie. The attacker must already possess a copy of a valid token; obtaining one is o [truncated]
CVE-2026-75158 debrief: Apache Airflow asset event enumeration. Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. This allowed authenticated users with asset-read access to enumerate asset events for Dags they are not authorized to see, potentially leading to unauthorized access or reco [truncated]
CVE-2026-91867 is a denial-of-service vulnerability in Apache Neethi. When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer. This allows a server to trickle bytes slowly and keep the fetch alive indefinitely, tying up the calling thread. The vulnerability can lead to system resource exhaustion and impact system availability. Defenders and system administra [truncated]
CVE-2026-91864 is a high-severity vulnerability in Apache Neethi, a denial-of-service (DoS) issue caused by the library's handling of WS-Policy documents. The vulnerability allows an attacker to craft a WS-Policy document that can cause a heap exhaustion due to unlimited content being copied into memory without proper size limits. Users are recommended to upgrade to version 3.2.4 to fix this issue.
CVE-2026-75157 debrief: Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any authenticated user who could read a Dag could therefore delete that Dag's queued asset events, silently suppressing asset-triggered scheduling for it. This vulnerability affects deployments using asset-triggered scheduling with wide read access to Dags. [truncated]
Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLocal value outlives the OSGi bundle that created it, repeated bundle or feature install, update, or refresh operations can leave successive bundle ClassLoader's pinned in memory and unreachable for garbage collection, leading to unbounded Metaspace growth and event [truncated]
Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components without rejected parent-directory names, and the path-containment check compared an unnormalized resolved path. An authenticated user [truncated]
Apache NiFi 2.11.0 has a vulnerability where an authenticated user with read access to a Connector can enumerate version-controlled Process Groups outside their granted read policies and a user with write access to a Connector can migrate a Process Group without write access to that Process Group. Upgrading to Apache NiFi 2.12.0 mitigates the issue by enforcing authorization checks.
Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition. Framework authorization for these methods was limited to read and write privileges on the Process Group itself, unlike the corresponding asynchronous update request methods. This issue allows an authenticated user with write access to a Process Group to sup [truncated]
CVE-2026-81866 is a low-severity vulnerability in Apache NiFi 2.9.0 through 2.11.0 that allows an authenticated user to apply Secret values backed by a Parameter Provider without proper authorization. The vulnerability arises from the lack of authorization checking on Assets and Secrets referenced in proposed configuration updates and verifications. This issue affects Apache NiFi installations with custom [truncated]
Apache NiFi 2.11.0 has a vulnerability where it disabled support for gzip-encoded HTTP requests for the application REST API but did not properly enforce this restriction. This allowed crafted requests to consume excessive memory. The framework enforcement filter did not check multiple instances of the Content-Encoding header and did not reject non-standard identifiers for gzip encoding. Upgrading to Apac [truncated]
CVE-2026-86792 debrief: Apache Airflow Apache Kafka provider vulnerability allows for arbitrary code execution in the control plane when the Kafka event producer is enabled. This occurs because the provider resolves dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with no allowlist, and hands them to the confluent-kafka client which invokes them. D [truncated]
CVE-2026-86466 debrief: Apache Airflow FAB provider vulnerability allows authentication bypass using a valid token from another client application. The vulnerability affects deployments using the FAB auth manager with Authentik OAuth. An attacker holding a token that the same Authentik identity provider minted for a different client application can present it to Airflow and be authenticated as the user it [truncated]
Apache ZooKeeper is vulnerable to log injection attacks. An unauthenticated attacker can inject fake log lines into ZooKeeper's operational log by sending a crafted add_auth request containing newline characters. This issue affects ZooKeeper versions 3.9.0 through 3.9.5 and 3.8.0 through 3.8.6. Users are recommended to upgrade to version 3.8.7 or 3.9.6.
Apache ZooKeeper's audit log is vulnerable to log injection attacks when audit logging is enabled. An unauthenticated attacker can inject arbitrary fields into the audit log by sending a digest authentication request with tab characters embedded in the username, allowing them to spoof audit results, forge operation types, and corrupt forensic evidence.
CVE-2026-82310 debrief: Apache Airflow FAB provider token acceptance issue after user deactivation. The vulnerability allows tokens issued to deactivated user accounts to remain valid, enabling continued access to the Core API. This affects deployments using Airflow 3 with the FAB auth manager and Core API token authentication. Airflow administrators and security teams should assess exposure and verify th [truncated]
Apache ZooKeeper's `deleteContainer` opcode allows unauthorized deletion of znodes, bypassing ACL restrictions. This issue affects versions 3.9.0-3.9.5 and 3.8.0-3.8.6. Users should upgrade to 3.9.6 or 3.8.7. The vulnerability allows authenticated clients to delete specific znodes in the data tree regardless of ACL restrictions on the znode or its parent. The `deleteContainer` opcode is considered interna [truncated]
Apache Airflow Keycloak provider vulnerability allows unauthenticated token endpoint access with client-credentials grant for any confidential client in the Keycloak realm, enabling Airflow login with unrelated application credentials. This issue affects deployments using the Keycloak auth manager whose realm is shared with other confidential clients. The attacker needs valid credentials for any one of th [truncated]
CVE-2026-76186 debrief: Apache Airflow Keycloak provider vulnerability allows unauthorized privilege escalation via mismatched session identity and Keycloak tokens. A user with a valid Airflow login can pair their session with another subject's Keycloak access or refresh token, potentially leading to unauthorized privilege escalation in deployments running Airflow 3.3 or later with the Keycloak auth manag [truncated]
Apache ZooKeeper quorum TLS fails to enforce peer hostname verification in FIPS-mode deployments. When sslQuorum=true, zookeeper.fips-mode=true, ssl.quorum.hostnameVerification=true, and ssl.quorum.clientHostnameVerification=true are enabled, the Java SSLSocket quorum path accepts a CA-trusted peer certificate whose SAN does not match the connected host. A malicious or misissued peer certificate can there [truncated]
Apache ZooKeeper's incomplete fix for CVE-2024-23944 allows information disclosure via SetWatches reconnect replay due to missing ACL checks. An attacker can discover ACL-restricted paths by registering exists-watches on non-existent paths and reconnecting after path creation with restricted ACLs. The issue exposes paths, not znode data, but paths may contain sensitive information like user names or login [truncated]
CVE-2026-86462 debrief: Apache Airflow FAB provider vulnerability allows continued access after password change. The issue arises from the Admin user-edit PATCH endpoint not invalidating existing database-backed sessions when a user's password is changed. This affects deployments using the FAB auth manager with database-backed sessions. Administrators and users should assess exposure and prioritize upgrad [truncated]
CVE-2026-82311 debrief: The Apache Airflow FAB provider's password reset functionality does not delete existing database-backed sessions, allowing an attacker with a victim's session cookie to maintain access after a password change. This affects deployments using the FAB auth manager with session_backend=database. The issue is fixed in version 3.9.0, addressing both CVE-2026-82311 and CVE-2026-86462. Def [truncated]
CVE-2026-82617 is a critical vulnerability in Apache OpenNLP, affecting versions from 2.0.0 through 2.5.11 and 3.0.0-M1 through 3.0.0-M5. The issue arises from ambiguous nested quantifiers in the DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URL patterns, which can lead to super-linear backtracking or unbounded matcher recursion when processing untrusted text. This can be exploited to caus [truncated]
A denial-of-service vulnerability exists in Apache OpenNLP's SymSpellModelSerializer. An attacker can cause an OutOfMemoryError by crafting a malicious .bin model file with large count fields, leading to a potential crash of the JVM. This issue affects versions 3.0.0-M4 and 3.0.0-M5. Users should upgrade to 3.0.0-M6 or apply mitigations. The vulnerability is caused by the SymSpellModelSerializer.create() [truncated]
An authorization bypass vulnerability in Apache Camel K allows a tenant to potentially expose secrets belonging to other tenants or operator components through custom resource resolution. This issue affects Apache Camel K versions from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2, or 2.11.0. The vulnerability allows a tenant to reference secrets [truncated]
CVE-2026-80352 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource creation with the privileges of the operator. Affected versions are Apache Camel K from 2.0.0 before 2.9.3 and from 2.10.1 before 2.10.2. Users are recommended to upgrade to version 2.9.3, [truncated]