PatchSiren

Apache Software Foundation CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Apache Software Foundation CVE published 2026-09-25

CVE-2026-92609

CVE-2026-92609 debrief: Apache Qpid Broker-J session fixation vulnerability allows unauthorized access. Users should upgrade to version 10.1.1. This issue affects Apache Qpid Broker-J through 10.1.0, enabling remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. Defenders should assess exposure and p [truncated]

HIGH Apache Software Foundation CVE published 2026-09-25

CVE-2026-92608

CVE-2026-92608 debrief: Apache Qpid Broker-J is vulnerable to disruption via improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion, affecting versions through 10.1.0. This issue allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers. Defenders and administrators should verify affected versions, upgrade to version 10.1.1, and monitor for po [truncated]

MEDIUM Apache Software Foundation CVE published 2026-09-24

CVE-2026-97636

CVE-2026-97636 debrief: Apache Airflow HashiCorp provider vulnerability allows bypassing team-scope guard, potentially leading to unauthorized access in multi-team deployments using HashiCorp Vault secrets backend. Affected deployments should verify and update to version 4.8.0 or later. This vulnerability is similar to CVE-2026-86465, CVE-2026-68870, CVE-2026-68871, and CVE-2026-68872 in other secrets bac [truncated]

CRITICAL Apache Software Foundation CVE published 2026-09-21

CVE-2026-86473

CVE-2026-86473 debrief: Apache Airflow Core API logout endpoint fails to revoke session tokens presented as Authorization bearer headers, allowing an attacker with a valid token to maintain access after a victim logs out. This issue affects API clients that authenticate with a bearer token rather than the browser session cookie. The attacker must already possess a copy of a valid token; obtaining one is o [truncated]

MEDIUM Apache Software Foundation CVE published 2026-09-21

CVE-2026-75158

CVE-2026-75158 debrief: Apache Airflow asset event enumeration. Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. This allowed authenticated users with asset-read access to enumerate asset events for Dags they are not authorized to see, potentially leading to unauthorized access or reco [truncated]

MEDIUM Apache Software Foundation CVE published 2026-09-21

CVE-2026-91867

CVE-2026-91867 is a denial-of-service vulnerability in Apache Neethi. When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer. This allows a server to trickle bytes slowly and keep the fetch alive indefinitely, tying up the calling thread. The vulnerability can lead to system resource exhaustion and impact system availability. Defenders and system administra [truncated]

HIGH Apache Software Foundation CVE published 2026-09-21

CVE-2026-91864

CVE-2026-91864 is a high-severity vulnerability in Apache Neethi, a denial-of-service (DoS) issue caused by the library's handling of WS-Policy documents. The vulnerability allows an attacker to craft a WS-Policy document that can cause a heap exhaustion due to unlimited content being copied into memory without proper size limits. Users are recommended to upgrade to version 3.2.4 to fix this issue.

HIGH Apache Software Foundation CVE published 2026-09-18

CVE-2026-75157

CVE-2026-75157 debrief: Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any authenticated user who could read a Dag could therefore delete that Dag's queued asset events, silently suppressing asset-triggered scheduling for it. This vulnerability affects deployments using asset-triggered scheduling with wide read access to Dags. [truncated]

HIGH Apache Software Foundation CVE published 2026-09-17

CVE-2026-92230

Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLocal value outlives the OSGi bundle that created it, repeated bundle or feature install, update, or refresh operations can leave successive bundle ClassLoader's pinned in memory and unreachable for garbage collection, leading to unbounded Metaspace growth and event [truncated]

HIGH Apache Software Foundation CVE published 2026-09-16

CVE-2026-87976

Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components without rejected parent-directory names, and the path-containment check compared an unnormalized resolved path. An authenticated user [truncated]

LOW Apache Software Foundation CVE published 2026-09-16

CVE-2026-86089

Apache NiFi 2.11.0 has a vulnerability where an authenticated user with read access to a Connector can enumerate version-controlled Process Groups outside their granted read policies and a user with write access to a Connector can migrate a Process Group without write access to that Process Group. Upgrading to Apache NiFi 2.12.0 mitigates the issue by enforcing authorization checks.

MEDIUM Apache Software Foundation CVE published 2026-09-16

CVE-2026-82561

Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition. Framework authorization for these methods was limited to read and write privileges on the Process Group itself, unlike the corresponding asynchronous update request methods. This issue allows an authenticated user with write access to a Process Group to sup [truncated]

LOW Apache Software Foundation CVE published 2026-09-16

CVE-2026-81866

CVE-2026-81866 is a low-severity vulnerability in Apache NiFi 2.9.0 through 2.11.0 that allows an authenticated user to apply Secret values backed by a Parameter Provider without proper authorization. The vulnerability arises from the lack of authorization checking on Assets and Secrets referenced in proposed configuration updates and verifications. This issue affects Apache NiFi installations with custom [truncated]

HIGH Apache Software Foundation CVE published 2026-09-16

CVE-2026-70469

Apache NiFi 2.11.0 has a vulnerability where it disabled support for gzip-encoded HTTP requests for the application REST API but did not properly enforce this restriction. This allowed crafted requests to consume excessive memory. The framework enforcement filter did not check multiple instances of the Content-Encoding header and did not reject non-standard identifiers for gzip encoding. Upgrading to Apac [truncated]

HIGH Apache Software Foundation CVE published 2026-09-16

CVE-2026-86792

CVE-2026-86792 debrief: Apache Airflow Apache Kafka provider vulnerability allows for arbitrary code execution in the control plane when the Kafka event producer is enabled. This occurs because the provider resolves dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with no allowlist, and hands them to the confluent-kafka client which invokes them. D [truncated]

HIGH Apache Software Foundation CVE published 2026-09-16

CVE-2026-86466

CVE-2026-86466 debrief: Apache Airflow FAB provider vulnerability allows authentication bypass using a valid token from another client application. The vulnerability affects deployments using the FAB auth manager with Authentik OAuth. An attacker holding a token that the same Authentik identity provider minted for a different client application can present it to Airflow and be authenticated as the user it [truncated]

MEDIUM Apache Software Foundation CVE published 2026-09-16

CVE-2026-84501

Apache ZooKeeper is vulnerable to log injection attacks. An unauthenticated attacker can inject fake log lines into ZooKeeper's operational log by sending a crafted add_auth request containing newline characters. This issue affects ZooKeeper versions 3.9.0 through 3.9.5 and 3.8.0 through 3.8.6. Users are recommended to upgrade to version 3.8.7 or 3.9.6.

MEDIUM Apache Software Foundation CVE published 2026-09-16

CVE-2026-84439

Apache ZooKeeper's audit log is vulnerable to log injection attacks when audit logging is enabled. An unauthenticated attacker can inject arbitrary fields into the audit log by sending a digest authentication request with tab characters embedded in the username, allowing them to spoof audit results, forge operation types, and corrupt forensic evidence.

HIGH Apache Software Foundation CVE published 2026-09-16

CVE-2026-82310

CVE-2026-82310 debrief: Apache Airflow FAB provider token acceptance issue after user deactivation. The vulnerability allows tokens issued to deactivated user accounts to remain valid, enabling continued access to the Core API. This affects deployments using Airflow 3 with the FAB auth manager and Core API token authentication. Airflow administrators and security teams should assess exposure and verify th [truncated]

HIGH Apache Software Foundation CVE published 2026-09-16

CVE-2026-79993

Apache ZooKeeper's `deleteContainer` opcode allows unauthorized deletion of znodes, bypassing ACL restrictions. This issue affects versions 3.9.0-3.9.5 and 3.8.0-3.8.6. Users should upgrade to 3.9.6 or 3.8.7. The vulnerability allows authenticated clients to delete specific znodes in the data tree regardless of ACL restrictions on the znode or its parent. The `deleteContainer` opcode is considered interna [truncated]

CRITICAL Apache Software Foundation CVE published 2026-09-16

CVE-2026-76187

Apache Airflow Keycloak provider vulnerability allows unauthenticated token endpoint access with client-credentials grant for any confidential client in the Keycloak realm, enabling Airflow login with unrelated application credentials. This issue affects deployments using the Keycloak auth manager whose realm is shared with other confidential clients. The attacker needs valid credentials for any one of th [truncated]

CRITICAL Apache Software Foundation CVE published 2026-09-16

CVE-2026-76186

CVE-2026-76186 debrief: Apache Airflow Keycloak provider vulnerability allows unauthorized privilege escalation via mismatched session identity and Keycloak tokens. A user with a valid Airflow login can pair their session with another subject's Keycloak access or refresh token, potentially leading to unauthorized privilege escalation in deployments running Airflow 3.3 or later with the Keycloak auth manag [truncated]

HIGH Apache Software Foundation CVE published 2026-09-16

CVE-2026-59969

Apache ZooKeeper quorum TLS fails to enforce peer hostname verification in FIPS-mode deployments. When sslQuorum=true, zookeeper.fips-mode=true, ssl.quorum.hostnameVerification=true, and ssl.quorum.clientHostnameVerification=true are enabled, the Java SSLSocket quorum path accepts a CA-trusted peer certificate whose SAN does not match the connected host. A malicious or misissued peer certificate can there [truncated]

HIGH Apache Software Foundation CVE published 2026-09-16

CVE-2026-59739

Apache ZooKeeper's incomplete fix for CVE-2024-23944 allows information disclosure via SetWatches reconnect replay due to missing ACL checks. An attacker can discover ACL-restricted paths by registering exists-watches on non-existent paths and reconnecting after path creation with restricted ACLs. The issue exposes paths, not znode data, but paths may contain sensitive information like user names or login [truncated]

CRITICAL Apache Software Foundation CVE published 2026-09-16

CVE-2026-86462

CVE-2026-86462 debrief: Apache Airflow FAB provider vulnerability allows continued access after password change. The issue arises from the Admin user-edit PATCH endpoint not invalidating existing database-backed sessions when a user's password is changed. This affects deployments using the FAB auth manager with database-backed sessions. Administrators and users should assess exposure and prioritize upgrad [truncated]

CRITICAL Apache Software Foundation CVE published 2026-09-16

CVE-2026-82311

CVE-2026-82311 debrief: The Apache Airflow FAB provider's password reset functionality does not delete existing database-backed sessions, allowing an attacker with a victim's session cookie to maintain access after a password change. This affects deployments using the FAB auth manager with session_backend=database. The issue is fixed in version 3.9.0, addressing both CVE-2026-82311 and CVE-2026-86462. Def [truncated]

CRITICAL Apache Software Foundation CVE published 2026-09-11

CVE-2026-82617

CVE-2026-82617 is a critical vulnerability in Apache OpenNLP, affecting versions from 2.0.0 through 2.5.11 and 3.0.0-M1 through 3.0.0-M5. The issue arises from ambiguous nested quantifiers in the DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URL patterns, which can lead to super-linear backtracking or unbounded matcher recursion when processing untrusted text. This can be exploited to caus [truncated]

HIGH Apache Software Foundation CVE published 2026-09-11

CVE-2026-67211

A denial-of-service vulnerability exists in Apache OpenNLP's SymSpellModelSerializer. An attacker can cause an OutOfMemoryError by crafting a malicious .bin model file with large count fields, leading to a potential crash of the JVM. This issue affects versions 3.0.0-M4 and 3.0.0-M5. Users should upgrade to 3.0.0-M6 or apply mitigations. The vulnerability is caused by the SymSpellModelSerializer.create() [truncated]

HIGH Apache Software Foundation CVE published 2026-09-10

CVE-2026-80354

An authorization bypass vulnerability in Apache Camel K allows a tenant to potentially expose secrets belonging to other tenants or operator components through custom resource resolution. This issue affects Apache Camel K versions from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2, or 2.11.0. The vulnerability allows a tenant to reference secrets [truncated]

CRITICAL Apache Software Foundation CVE published 2026-09-10

CVE-2026-80352

CVE-2026-80352 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource creation with the privileges of the operator. Affected versions are Apache Camel K from 2.0.0 before 2.9.3 and from 2.10.1 before 2.10.2. Users are recommended to upgrade to version 2.9.3, [truncated]