These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The CVE-2026-55993 vulnerability is an Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, and Server-Side Request Forgery (SSRF) issue in Apache Camel's Atmosphere Websocket Component. The vulnerability allows a client connecting to the WebSocket endpoint to set Camel-internal control headers, including CamelHttpUri, by supplying them as query parameters. This can lead [truncated]
The CVE record describes a critical vulnerability in the Apache Camel Keycloak Component, allowing for unauthenticated access and potential remote code execution due to improper authentication and missing authentication for critical functions. The vulnerability arises from the KeycloakSecurityPolicy in Apache Camel, which guards routes by running KeycloakSecurityProcessor.beforeProcess(). This processor p [truncated]
A Generation of Error Message Containing Sensitive Information vulnerability exists in Apache Camel Netty HTTP component. The camel-netty-http HTTP server consumer exposes a muteException option that controls what is returned to the client when a route processing error occurs. By default, this option is set to false, causing the consumer to write the full Throwable stack trace into the HTTP response body [truncated]
The CVE record describes an Improper Input Validation vulnerability in the Apache Camel Cometd Component. The vulnerability allows an attacker to inject arbitrary Camel control headers that influence the behavior of downstream producers in the route. This issue affects Apache Camel versions from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, and from 4.19.0 before 4.21.0. The vulnerability has a CVSS sco [truncated]
CVE-2026-24013 is an Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing openSession authentication, receive valid query results. This allows authentication bypass and unauthorized reading of time-series data. The issue affects [truncated]
CVE-2026-24012 is an Uncontrolled Resource Consumption vulnerability in Apache IoTDB. The issue arises from certain interfaces failing to impose reasonable limits on query time spans and aggregation intervals. An attacker can construct a request with extreme parameters, such as a very large time range combined with a minimal interval, forcing the DataNode to build an enormous result set in memory. This ex [truncated]
CVE-2026-47898 is an Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). The issue affects Apache Lucene.Net.Analysis.Common versions from 4.8.0-beta00005 before 4.8.0-beta00018. Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue. This vulnerability allows attackers to potentially read or execute loc [truncated]
A Path Traversal vulnerability was discovered in the Apache Lucene.Net.Replicator library, impacting versions from 4.8.0-beta00005 up to but not including 4.8.0-beta00018. This vulnerability allows attackers to potentially access files and directories outside of the intended restricted directory due to improper limitation of a pathname. Users are advised to upgrade to version 4.8.0-beta00018 to address th [truncated]
A critical vulnerability in Apache IoTDB allows path traversal attacks. Affected versions include Apache IoTDB 1.0.0 to 1.3.5 and 2.0.0 to 2.0.6. Users should upgrade to version 1.3.6 or 2.0.7 to fix the issue. This vulnerability requires immediate attention from defenders and administrators to prevent potential attacks and data breaches. The affected systems should be assessed for exposure, and upgrading [truncated]
CVE-2025-55017 is a Path Traversal vulnerability in Apache IoTDB, affecting versions from 2.0.0 before 2.0.6 and from 1.0.0 before 1.3.6. This issue allows for unauthorized access to restricted directories, potentially leading to data exposure or integrity issues. Users should assess their exposure and upgrade to fixed versions 1.3.6 and 2.0.6. It is crucial for defenders and administrators to verify and [truncated]
CVE-2026-49486 debrief: Apache Airflow FTP provider's FTPSHook.get_conn() created an ftplib.FTP_TLS connection but never called prot_p(), exposing file contents and credentials-in-transit. The vulnerability allows a network attacker to observe the data connection, potentially leading to unauthorized access and data breaches. Upgrade apache-airflow-providers-ftp to 3.15.1 or later to encrypt the data chann [truncated]
CVE-2025-62198 is an authenticated user cross-site scripting (XSS) vulnerability in Apache Atlas versions 2.4.0 and earlier. The issue allows an authenticated user to perform XSS. Defenders should assess their exposure and prioritize upgrading to version 2.5.0, which fixes the issue. This vulnerability has a significant impact on the security posture of affected systems, and defenders should take immediat [truncated]
CVE-2026-49872 is an Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can possibly authenticate with credentials from a different source. This issue affects Apache APISIX versions from 3.0.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue. The CVSS score is 5.3, indicating a medium severity vulnerabil [truncated]
CVE-2026-49871 is a Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin of Apache APISIX. Under default configurations, a remote attacker can send a victim to a controlled webpage, causing the victim's browser to become authenticated as a different identity. Actions taken by the victim are then attributed to the attacker's identity. This issue affects Apache APISIX versions from 3.0.0 t [truncated]
CVE-2026-49231 is an Authentication Bypass by Spoofing vulnerability in the opa plugin of Apache APISIX. An attacker could relay spoofed identity headers to the upstream service, assuming higher privileges, due to non-default configuration. Affected versions are from 3.5.0 through 3.16.0. Users should upgrade to version 3.17.0. This issue has a CVSS score of 2.3 and is considered LOW severity.
CVE-2026-49230 is a MEDIUM-severity vulnerability in Apache APISIX, affecting versions from 3.8.0 through 3.16.0. The issue lies in the jwe-decrypt plugin, which under default configuration, is vulnerable to authentication bypass. Defenders should prioritize upgrading to version 3.17.0, which fixes the issue. This vulnerability has a CVSS score of 6.3, indicating moderate risk.
CVE-2026-48895 is an Open Redirect vulnerability in Apache APISIX, a popular open-source API gateway. An attacker could manipulate client headers to perform an open redirect, potentially exposing the session token. This issue affects Apache APISIX versions from 3.0.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue. The CVSS score for this vulnerability is 2.1, ind [truncated]
CVE-2026-47341 is a medium-severity Authentication Bypass by Capture-replay vulnerability in Apache APISIX. The issue arises from certain configurations in hmac-auth, allowing an attacker to reuse a token indefinitely and bypass expiry. This vulnerability affects Apache APISIX versions from 3.11.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0 to fix the issue. The CVSS score for this [truncated]
CVE-2026-44087 is a MEDIUM-severity vulnerability in Apache APISIX's openid-connect plugin. Under default configuration, an attacker can spoof identity headers to access protected resources without authorization. This Insufficient Verification of Data Authenticity issue affects Apache APISIX versions from 2.3 to 3.16.0. Defenders should prioritize upgrading to version 3.17.0, which fixes the issue. The vu [truncated]
CVE-2026-44046 is a low-severity vulnerability in Apache APISIX, affecting versions from 1.2.0 through 3.16.0. The issue allows attackers to potentially pollute logs with spoofed identity information and exploit IP-based access control rules using the wolf-rbac plugin under default configuration. Defenders should assess their exposure and prioritize upgrading to version 3.17.0, which fixes the issue. The [truncated]
CVE-2026-39998 is a MEDIUM-severity Improper Input Validation vulnerability in Apache APISIX, affecting versions from 2.12.0 through 3.16.0. An attacker can exploit certain configurations in the forward-auth plugin to spoof identity headers. Users should upgrade to version 3.17.0 to fix the issue. This vulnerability has a CVSS score of 5.8 and was published on June 19, 2026.
A path traversal vulnerability was discovered in the SFTP provider of Apache Airflow, specifically in the `SFTPHook.retrieve_directory` and `SFTPOperator(operation=get)` functions. This vulnerability allows a malicious or compromised remote SFTP server to write files outside the configured local destination directory via crafted directory-entry names. The attack surface includes any deployment that downlo [truncated]
CVE-2026-42357 is a medium-severity vulnerability in Apache DolphinScheduler that allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue. The vulnerability has a CVSS score of 6.5 and is classified as CWE-86 [truncated]
CVE-2026-41280 is a MEDIUM-severity vulnerability in Apache DolphinScheduler, affecting versions prior to 3.4.2. The issue allows users with system login privileges to delete task definitions in unauthorized projects, posing a risk to data integrity and project management. Users should upgrade to version 3.4.2, which fixes this issue. This vulnerability has a CVSS score of 4.9 and is categorized under CWE [truncated]
CVE-2026-32967 is a critical Incorrect Authorization vulnerability in Apache DolphinScheduler's `/v2` experimental interface. The issue affects all versions before 3.4.2 and has a CVSS score of 9.1. Users should upgrade to version 3.4.2 to fix the issue. This vulnerability allows unauthorized access, potentially leading to data breaches or system compromise. Organizations using Apache DolphinScheduler sho [truncated]
Apache DolphinScheduler versions before 3.4.2 are vulnerable to a critical issue (CVSS 9.8) due to a missing authorization check in the DataSource API. This oversight allows for arbitrary data source metadata disclosure. The vulnerability, tracked as CVE-2026-32966, was made public on June 17, 2026. Users of affected versions are strongly advised to upgrade to version 3.4.2, which addresses this issue. Th [truncated]
CVE-2026-50645 is a HIGH severity vulnerability in Apache CXF, with a CVSS score of 7.5. The vulnerability occurs because there is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this i [truncated]
A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted 'Content-Type' or protected HTTP-header metadata came from a verified signature entry, and may steer downstream JAX-RS entity parsing or signed-header consistency checks. Users are re [truncated]
CVE-2026-50633 is a HIGH severity vulnerability in Apache CXF's JCA integration module. The vulnerability is caused by a JNDI Injection issue, which can allow for code execution if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
CVE-2026-50632 is a HIGH-severity vulnerability (CVSS Score: 8.1) in Apache CXF, which is an incomplete fix for a previous advisory CVE-2026-44417. This vulnerability can allow code execution capabilities if untrusted users are allowed to configure JMS for Apache CXF. The issue was published on 2026-06-12T10:16:23.183Z and last modified on 2026-06-12T18:58:03.547Z.