PatchSiren

Apache Software Foundation CVE debriefs · Page 4

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Apache Software Foundation CVE published 2026-08-21

CVE-2026-59780

The CVE-2026-59780 vulnerability is an Exposure of Sensitive Information to an Unauthorized Actor issue in Apache CloudStack's LDAP authentication plugin. LDAP configurations can be listed by any authenticated user with access to the listLdapConfigurations API. By default, this API is available to all default roles. The issue affects Apache CloudStack versions from 4.2.0.0 through 4.20.3.0 and from 4.21.0 [truncated]

HIGH Apache Software Foundation CVE published 2026-08-21

CVE-2026-59657

A Cleartext Storage of Sensitive Information vulnerability exists in Apache CloudStack with AsyncJob storage in the database. This issue affects Apache CloudStack versions from 4.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. The vulnerability allows unauthorized access to sensitive information. Affected deployments should prioritize upgrading to a fixed version. Evidence is limited to the CVE r [truncated]

HIGH Apache Software Foundation CVE published 2026-08-21

CVE-2026-59655

Apache CloudStack's OAuth authentication plugin exposure of sensitive information to unauthorized actors while listing OAuth providers affects versions from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. This issue allows unauthorized actors to access sensitive information. Users should upgrade to 4.20.3.1 or 4.22.1.1 or later. Evidence of exposure and potential impact should be verified by [truncated]

HIGH Apache Software Foundation CVE published 2026-08-21

CVE-2026-50222

Apache CloudStack, a software for building public and private clouds, contains a vulnerability (CVE-2026-50222) that could allow unauthorized access to sensitive user data. The issue arises from several user data-related APIs, including deleteUserData, linkUserDataToTemplate, resetUserDataForVirtualMachine, deployVirtualMachine, and updateVirtualMachine, which have missing or insufficient access control v [truncated]

HIGH Apache Software Foundation CVE published 2026-08-21

CVE-2026-50112

CVE-2026-50112 involves SSRF and RCE vulnerabilities in Apache CloudStack, allowing an authenticated tenant to register a template pointing to an attacker-controlled metalink file, potentially leading to cross-tenant root access on the KVM hypervisor host. Affected versions include Apache CloudStack from 4.14.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to vers [truncated]

HIGH Apache Software Foundation CVE published 2026-08-21

CVE-2026-47359

The CVE-2026-47359 record describes an OS command injection vulnerability in Apache CloudStack's NAS backup provider plugin. The addBackupRepository API and updateBackupRepository API accept unsanitized command options, allowing a malicious operator account to inject arbitrary commands that execute on the KVM hypervisor host during backup restore operations. This issue affects Apache CloudStack versions f [truncated]

Review Apache Software Foundation CVE published 2026-08-15

CVE-2026-73635

An executive overview of CVE-2026-73635: Apache Struts users should be aware of an allocation of resources without limits or throttling vulnerability. This vulnerability can cause the framework's internal localized-text caches to grow without bound and exhaust the Java heap, denying service to other users. The CVE record was published on 2026-08-15T11:16:27.540Z and has not been modified since then. Affec [truncated]

Review Apache Software Foundation CVE published 2026-08-15

CVE-2026-73634

The CVE-2026-73634 record describes an uncontrolled resource consumption vulnerability in Apache Struts, affecting versions from 6.0.0 through 6.10.0 and from 7.0.0 through 7.2.1. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, allowing a single request to exhaust the heap and deny [truncated]

HIGH Apache Software Foundation CVE published 2026-08-13

CVE-2026-66256

CVE-2026-66256: Apache Shindig Deserialization of Untrusted Data Vulnerability allows for arbitrary code execution on the server. Users with access to the Shindig REST API can send specially-crafted requests to trigger this vulnerability. As the project is retired, defenders should restrict access to trusted users and consider finding an alternative. The vulnerability has a high severity score and require [truncated]

MEDIUM Apache Software Foundation CVE published 2026-08-12

CVE-2026-68969

Apache Airflow's audit log contained cleartext Variable values and Connection `extra` contents when submitted through bulk endpoints. Authenticated users with audit-log read access could recover secrets verbatim. The Airflow UI's Import Variables action also wrote secrets to the log. This vulnerability allows unauthorized access to sensitive information. Users should upgrade to apache-airflow 3.3.1 or lat [truncated]

MEDIUM Apache Software Foundation CVE published 2026-08-12

CVE-2026-65017

Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. An authenticated Viewer with configuration-read access could read a team-scoped Celery broker URL, including its embedded credentials, in cleartext. This issue allows unauthorized access to sensitive information. Users are advised to upgrade to apache-airflow 3.3.1 or later to address this vulner [truncated]

MEDIUM Apache Software Foundation CVE published 2026-08-12

CVE-2026-59242

CVE-2026-59242 debrief based on the supplied source corpus. Apache Airflow's XCom endpoint allows an authenticated API user with XCom write-and-read access to instantiate arbitrary airflow.* classes on the API server due to CWE-502. This vulnerability, with a CVSS score of 5.4 and a severity of MEDIUM, was published on 2026-08-12T16:17:09.067Z and has not been modified since then. The CVE record and NVD e [truncated]

MEDIUM Apache Software Foundation CVE published 2026-08-12

CVE-2026-68868

CVE-2026-68868 debrief: Apache Airflow's Google provider has a vulnerability in the Google Cloud Secret Manager secrets backend. The backend failed to apply the team scope when resolving Connections and Variables. This issue allows tasks or Dags from one team to resolve and obtain credentials for Connections or Variables from another team in multi-team mode.

CRITICAL Apache Software Foundation CVE published 2026-08-11

CVE-2026-71290

CVE-2026-71290 is an Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. The vulnerability allows an attacker to impersonate a server by presenting a valid certificate for a different domain when using the async version of HttpClient with HostnameVerificationPolicy#BUILTIN setting. The classic version of HttpClient is not affected. Defenders handling sensitive da [truncated]

MEDIUM Apache Software Foundation CVE published 2026-08-10

CVE-2026-68872

CVE-2026-68872 debrief: Apache Airflow's Amazon provider has a vulnerability allowing a caller in one team to resolve a secret belonging to another team when using AWS Systems Manager Parameter Store and Secrets Manager backends in multi-team mode. The vulnerability exists due to the AWS Systems Manager Parameter Store and Secrets Manager backends resolving a team-scoped Connection or Variable id through [truncated]

MEDIUM Apache Software Foundation CVE published 2026-08-10

CVE-2026-68871

CVE-2026-68871 debrief: Apache Airflow Yandex provider vulnerability allows unauthorized secret access in multi-team mode, enabling a caller in one team to resolve secrets belonging to another team. This occurs when the Yandex Lockbox secrets backend resolves team-scoped Connection or Variable ids through team-agnostic lookup if the team-scoped lookup misses. The vulnerability requires enabling multi-team [truncated]

HIGH Apache Software Foundation CVE published 2026-08-10

CVE-2026-61899

A vulnerability exists in Apache Tapestry 5.5.0+ on all platforms, allowing attackers to download classpath assets via specially crafted URLs. This issue poses a significant risk to users of Apache Tapestry 5.5.0+ as it could potentially lead to unauthorized access to sensitive data. Users are recommended to upgrade to version 5.9.1, which fixes this issue. It is crucial for operators, platform administra [truncated]

HIGH Apache Software Foundation CVE published 2026-08-10

CVE-2026-55814

CVE-2026-55814 is a missing authentication issue in Apache Ranger Download APIs versions <= 2.8.0. This vulnerability allows unauthorized access to download APIs, potentially impacting system security and data integrity. Apache Ranger users and administrators should verify their systems for potential exposure and review system configurations. The issue has not been modified since its publication on 2026-0 [truncated]

CRITICAL Apache Software Foundation CVE published 2026-08-10

CVE-2026-44416

CVE-2026-44416 is a Remote Code Execution vulnerability via Arbitrary Class Instantiation in the plugin-schema-registry component of Apache Ranger versions <= 2.8.0. This vulnerability allows attackers to execute arbitrary code, potentially leading to a complete compromise of the affected system. The CVE record was published on 2026-08-10T11:17:26.547Z and has not been modified since then. However, the fu [truncated]

CRITICAL Apache Software Foundation CVE published 2026-08-10

CVE-2026-42537

CVE-2026-42537 is a Remote Code Execution vulnerability via JDBC URL Injection in Apache Ranger versions <= 2.8.0. The issue is addressed in version 2.9.0. Apache Ranger users should prioritize upgrading to version 2.9.0 and review JDBC URL configurations to prevent exploitation. Limited evidence suggests Apache Ranger users should verify affected deployments, review compensating controls, and monitor for [truncated]

Review Apache Software Foundation CVE published 2026-08-10

CVE-2026-44630

Apache IoTDB RPC service vulnerability allows remote unauthenticated attackers to cause denial of service via crafted Thrift frame. Affected versions: Apache IoTDB before 1.3.8, 2.0.0 to 2.0.9. Upgrade to 2.0.10 to fix. The vulnerability is caused by improper validation of length fields in the Apache IoTDB RPC service, which can lead to excessive memory allocation and a crash with an OutOfMemoryError. Sec [truncated]

HIGH Apache Software Foundation CVE published 2026-08-06

CVE-2026-34502

CVE-2026-34502 is a heap-based buffer overflow vulnerability in the Apache Portable Runtime Utility (APR-Util) memcached client, affecting versions from 1.3.0 through 1.6.3. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. The CWE associated with this vulnerability is CWE-122. The vulnerability can be exploited by sending a specially crafted request to the memcached client, po [truncated]

CRITICAL Apache Software Foundation CVE published 2026-08-06

CVE-2026-34191

The CVE record for CVE-2026-34191 was published on 2026-08-06T15:16:54.650Z and has not been modified since then. The NVD entry is currently Analyzed. This SQL injection vulnerability in Apache Portable Runtime Utility has a critical CVSS score of 9.1 and requires immediate attention. Organizations using affected versions should prioritize patching to prevent potential SQL injection attacks. The vulnerabi [truncated]

HIGH Apache Software Foundation CVE published 2026-08-06

CVE-2026-68481

Apache CXF's DefaultEncryptingOAuthDataProvider incorrectly handles revoked access and refresh tokens, allowing them to decrypt successfully and be reported as active by TokenIntrospectionService, contrary to RFC requirements. This vulnerability affects users of Apache CXF, particularly those using DefaultEncryptingOAuthDataProvider for token management. The issue involves improper invalidation of revoked [truncated]

CRITICAL Apache Software Foundation CVE published 2026-08-06

CVE-2026-68079

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T12:16:28.060Z and has not been modified since then. Apache CXF's DefaultEncryptingCodeDataProvider has a flaw in the implementation of the removeCodeGrant functionality, allowing a captured authorization code to be redeemed an unlimited number of times. This violates the RFC requirement that 'The [truncated]

CRITICAL Apache Software Foundation CVE published 2026-08-06

CVE-2026-65583

Apache CXF's OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, self-issued ID tokens are not accepted by default in the validator. The vulnerability's technical impact is significant, as it allows for potential authentication bypass. [truncated]

CRITICAL Apache Software Foundation CVE published 2026-08-06

CVE-2026-63687

Apache CXF's JwtRequestCodeFilter vulnerability allows a client with a validly-signed request JWT to substitute sensitive values, undermining PKCE integrity and OpenID Connect replay protection. Affected product deployments should be reviewed for potential security risks. The CVE record was published on 2026-08-06T12:16:27.843Z and has not been modified since then. This issue affects Apache CXF users, sec [truncated]

CRITICAL Apache Software Foundation CVE published 2026-08-06

CVE-2026-61466

Apache CXF's OAuth2 Dynamic Client Registration endpoint is vulnerable due to lack of validation against an AS-defined allowlist, potentially allowing scope elevation. Affected product deployments should be identified and reviewed for exposure. The CVE record was published on 2026-08-06T12:16:27.730Z. Users should review the official advisory and plan vendor-supported updates or mitigations.

CRITICAL Apache Software Foundation CVE published 2026-08-06

CVE-2026-66909

Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserial [truncated]

HIGH Apache Software Foundation CVE published 2026-08-06

CVE-2026-65432

Apache CXF is vulnerable to XML External Entity (XXE) attacks due to improper handling of imported WSDL/XSD content. The vulnerability exists because while the top-level WSDL is processed with protections against XML DTDs and external entities, any imported documents are handled by WSDL4J without these protections. This issue affects users of Apache CXF, especially those using versions prior to 3.6.12, 4. [truncated]