PatchSiren

Apache Software Foundation CVE debriefs · Page 7

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Apache Software Foundation CVE published 2026-07-20

CVE-2026-56623

A path traversal vulnerability exists in Apache MINA SSHD component sshd-git on Windows, allowing authenticated remote users to access git repositories outside the configured server-side root directory. This issue arises from incomplete path validation for CVE-2026-48827 in Apache MINA SSHD 2.18.0 and 3.0.0-M4 on Windows. Affected applications use org.apache.sshd:sshd-git to implement git servers on Windo [truncated]

HIGH Apache Software Foundation CVE published 2026-07-20

CVE-2026-56452

A path traversal vulnerability exists in the sshd-scp component of Apache MINA SSHD, a Java library for client-side and server-side SSH. The implementation of receiving files or directories via SCP did not validate filenames in SCP 'C' or 'D' commands, allowing a malicious sender to send filenames containing paths and write files to attacker-controlled locations.

CRITICAL Apache Software Foundation CVE published 2026-07-20

CVE-2026-63071

CVE-2026-63071 is an Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code, bypassing the Groovy security sandbox. This issue affects Apache Syncope versions from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.6, and from 4.1.0-M0 through 4.1.1. Users are [truncated]

HIGH Apache Software Foundation CVE published 2026-07-20

CVE-2026-62418

A Server-Side Request Forgery (SSRF) vulnerability was found in Apache Syncope, affecting versions from 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1. This SSRF issue arises from a lack of proper validation in the Connectors and Resources check, allowing an attacker with low privileges and authenticated access to potentially exploit this vulnerability. The vulnerability has a [truncated]

CRITICAL Apache Software Foundation CVE published 2026-07-20

CVE-2026-62183

CVE-2026-62183 is an Improper Privilege Management vulnerability in Apache Syncope. When specific user workflow adapters are configured, a REST API call can allow a user to grant themselves admin roles, gaining entitlements and effectively becoming an administrator. The actual entitlements gained depend on the defined roles in the Syncope deployment. This issue affects Apache Syncope versions 3.0.0-M0 thr [truncated]

CRITICAL Apache Software Foundation CVE published 2026-07-20

CVE-2026-57308

The CVE record for CVE-2026-57308 was published on 2026-07-20T15:16:44.197Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope allows an administrator with adequate entitlements to achieve execution of arbitrary SQL via stacked queries, leveraging uns [truncated]

CRITICAL Apache Software Foundation CVE published 2026-07-20

CVE-2026-53421

CVE-2026-53421 is an Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts. Affected versions include 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1. Users are reco [truncated]

CRITICAL Apache Software Foundation CVE published 2026-07-20

CVE-2026-53405

CVE-2026-53405 is an Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. When a BPMN process containing a Groovy scriptTask is imported and started, the Groovy script is executed directly on the server, with no sandbox. Affected versions include 3.0 [truncated]

HIGH Apache Software Foundation CVE published 2026-07-18

CVE-2026-59173

CVE-2026-59173 is an Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. The issue affects Apache Traffic Server versions from 9.0.0 through 9.1.13 and from 10.0.0 through 10.1.2. Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue. This vulnerability can lead to resource exhaustion, potentially causing performance issues or crashes. Affected users sho [truncated]

MEDIUM Apache Software Foundation CVE published 2026-07-17

CVE-2026-62764

CVE-2026-62764 is an Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user without system permissions may issue a remote command to gracefully shutdown system components (compaction-coordinator, compactor, gc, manager, monitor, tserver, or sserver), leading to a denial of service. This issue affects Apache Accumulo 2.1.4 and 2.1.5. Users a [truncated]

Review Apache Software Foundation CVE published 2026-07-14

CVE-2026-58319

CVE-2026-58319: Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and availability and leading to cluster instability or denial of service. This issue affects Apache Doris versions prior to 3.1.0. The [truncated]

Review Apache Software Foundation CVE published 2026-07-14

CVE-2026-59084

Apache Tomcat has an Insufficient Technical Documentation vulnerability. The EncryptInterceptor configuration requirements were not clearly documented. This issue affects multiple Apache Tomcat versions, including 11.0.0-M1 through 11.0.23, 10.1.0-M1 through 10.1.56, 9.0.13 through 9.0.119, 8.5.38 through 8.5.100, and 7.0.100 through 7.0.109. Users are recommended to review and upgrade to fixed versions. [truncated]

Review Apache Software Foundation CVE published 2026-07-14

CVE-2026-59083

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T09:16:41.483Z and has not been modified since then. This Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allows security constraint bypass for some configurations. Affected versions include Apache Tomcat 11.0.0-M1 through 11.0.23, 10.1.0-M1 through [truncated]

HIGH Apache Software Foundation CVE published 2026-07-13

CVE-2026-59245

A high-severity vulnerability was found in the Apache Airflow FAB auth manager. A DAG named 'DAGs' colliding with the global all-DAGs permission resource name produced by resource_name() could allow a user granted per-DAG access_control on that DAG to be silently granted the global all-DAGs permission, leading to privilege escalation. This issue arises when a DAG named 'DAGs' exists and a lower-privileged [truncated]

HIGH Apache Software Foundation CVE published 2026-07-13

CVE-2026-58065

The Apache Airflow Git provider's default SSH host-key verification setting allows for man-in-the-middle attacks, enabling an attacker to impersonate the Git server and capture SSH deploy keys or inject malicious repository content. This vulnerability affects deployments using the Git DAG bundle or Git provider to clone over SSH with a deploy key. Defenders responsible for Apache Airflow deployments shoul [truncated]

CRITICAL Apache Software Foundation CVE published 2026-07-13

CVE-2026-41041

A URL path injection via unencoded user-supplied identifiers vulnerability was reported in Apache Gravitino, affecting versions from 1.0.0 before 1.2.1. This issue allows attackers to inject malicious URLs, potentially leading to unauthorized access or data breaches. Users are recommended to upgrade to version 1.2.1 to fix the issue. The vulnerability has a medium defensive priority, and users should revi [truncated]

MEDIUM Apache Software Foundation CVE published 2026-07-10

CVE-2026-49844

CVE-2026-49844 involves improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API, producing output that is not valid JSON. This defect is reachable when an application uses the message resolver of JsonTemplateLayout or other layouts that rely on MapMessage.asJson() or MapMessage.getFormattedMessage and logs a MapMessage with an attacker-controlled floa [truncated]

HIGH Apache Software Foundation CVE published 2026-07-10

CVE-2026-40454

The CVE record for CVE-2026-40454 was published on 2026-07-10T08:16:22.750Z and has not been modified since then. The NVD entry is currently Deferred. This Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client can cause the client process to crash on malformed server data. Affected versions include Apache IoTDB C++ client: from 1.3.5 before 1.3.8, from 2.0.5 before 2.0.10.

MEDIUM Apache Software Foundation CVE published 2026-07-10

CVE-2026-40009

CVE-2026-40009 is an Improper Privilege Management and Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate privileges to access the full tree path by renaming themselves to __internal_auditor. The issue affects Apache IoTDB versions from 2.0.8 to before 2.0.10. Users are advised to upgrade to version 2.0.10, which fixes the issue. This vulnerability has a CVSS score of [truncated]

HIGH Apache Software Foundation CVE published 2026-07-10

CVE-2026-40007

CVE-2026-40007 is an Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. The IoTDB AirGap receiver's readLength method calls itself recursively each time it recognises the E-language prefix in socket data, with no depth limit. An unauthenticated attacker can send a stream of repeated E-language prefixes that drives the recursion arbitrarily deep, exhausting the receive [truncated]

HIGH Apache Software Foundation CVE published 2026-07-10

CVE-2026-40006

CVE-2026-40006 is a high-severity vulnerability in Apache IoTDB, affecting versions from 1.0.0 before 2.0.10. The vulnerability allows unauthenticated attackers to cause a denial of service by exhausting heap memory through a specially crafted TCP connection. This issue arises when pipe_air_gap_receiver_enabled=true, allowing the IoTDB AirGap pipe receiver to accept raw TCP connections on port 9780 with n [truncated]

CRITICAL Apache Software Foundation CVE published 2026-07-10

CVE-2026-40005

CVE-2026-40005 is a Path Traversal vulnerability in Apache IoTDB. An attacker can write arbitrary files anywhere the IoTDB process has write permissions with an unsafe API. This issue affects Apache IoTDB versions from 1.0.0 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue. The vulnerability has a CVSS score of 9.1 and is considered CRITICAL. The IoTDB process has w [truncated]

CRITICAL Apache Software Foundation CVE published 2026-07-10

CVE-2026-28564

CVE-2026-28564 is a critical vulnerability in Apache IoTDB, affecting versions from 1.0.0 before 2.0.10. The issue involves Insufficient Session Expiration and Authentication Bypass by Capture-replay, allowing attackers to bypass authentication and potentially gain unauthorized access. Users are recommended to upgrade to version 2.0.10 to fix the issue. This vulnerability has a CVSS score of 9.8 and is co [truncated]

CRITICAL Apache Software Foundation CVE published 2026-07-08

CVE-2026-41042

CVE-2026-41042 is a critical vulnerability in Apache Gravitino, allowing unauthenticated execution of arbitrary Java code via a malicious H2 JDBC URL. This issue affects Apache Gravitino versions before 1.2.1 and is mainly relevant for testing and local development environments. The vulnerability has a CVSS score of 9.1 and is considered critical. Users are recommended to upgrade to version 1.2.1, which f [truncated]

MEDIUM Apache Software Foundation CVE published 2026-07-07

CVE-2026-49487

CVE-2026-49487 is a medium-severity vulnerability in Apache Airflow before 3.3.0. The REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking, potentially exposing sensitive information such as provider API keys. Defenders and administrators of Apache Airflow deployments should assess exposure and prioritize upgrading to Apache Airflow 3.3.0 or later to p [truncated]

MEDIUM Apache Software Foundation CVE published 2026-07-07

CVE-2026-49296

CVE-2026-49296 debrief: Apache Airflow DAG source disclosure. A vulnerability in Apache Airflow allows users authorized to read one DAG to disclose the source of other DAGs co-located in the same source file. This occurs because the `GET /api/v2/dagSources/{dag_id}` endpoint and the equivalent DAG-source view in the UI return the entire source file without redacting DAGs the caller was not authorized to r [truncated]

MEDIUM Apache Software Foundation CVE published 2026-07-07

CVE-2026-48892

CVE-2026-48892 debrief based on the supplied source corpus. The Config API in Apache Airflow did not redact per-key secrets-backend overrides, allowing authenticated UI/API users with Config read permission to retrieve plaintext secrets-backend credentials. This vulnerability affects deployments that configure secrets backends via per-key environment overrides. The vulnerability has a medium severity and [truncated]

MEDIUM Apache Software Foundation CVE published 2026-07-07

CVE-2026-48828

The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key. This prevented the key-based `should_hide_value_for_key` check from firing for JSON-decodable variable values. An authenticated UI/API user with bulk Variable read permission could retrieve plaintext values from JSON variables whose key would otherwise trigger redaction. Affects deployments storing sensitive v [truncated]

CRITICAL Apache Software Foundation CVE published 2026-07-07

CVE-2026-33264

CVE-2026-33264 is a remote code execution vulnerability in Apache Airflow. The bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG. A DAG author could embed a malicious trigger into a DAG to gain remote code execution on the API Server / Scheduler process, crossing the Airflow security bo [truncated]

HIGH Apache Software Foundation CVE published 2026-07-06

CVE-2026-43825

CVE-2026-43825 is a high-severity vulnerability in Apache OpenNLP's SvmDoccatModel, which allows for remote code execution via untrusted Java deserialization. The vulnerability affects versions before 3.0.0-M4 and is caused by the deserialize() method reading an attacker-controlled stream with java.io.ObjectInputStream and calling readObject() without an ObjectInputFilter installed. The practical impact i [truncated]