These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The CVE record for CVE-2026-40047 was published on 2026-07-06T09:16:35.377Z and remains unchanged. The vulnerability affects Apache Camel versions from 4.15.0 to before 4.18.3, allowing for argument injection and directory traversal attacks due to improper neutralization of argument delimiters in the Docling component. Users of affected versions should be concerned about potential system vulnerabilities. [truncated]
CVE-2026-47896 is a Path Traversal vulnerability in the Apache Lucene.Net.Replicator library, affecting versions from 4.8.0-beta00005 through 4.8.0-beta00017. This issue allows attackers to traverse directory paths, potentially leading to unauthorized access or data exposure. Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue. The vulnerability has a CVSS score of 8.9 and i [truncated]
CVE-2026-55955 is an Improper Authentication vulnerability in Apache Tomcat that allows a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat versions from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, and from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11. [truncated]
CVE-2026-49268 is a high-severity vulnerability in Apache Shiro that allows remote attackers to inject LDAP special characters, potentially bypassing authentication or impersonating users. The issue affects all Apache Shiro versions up to 2.2.0 and 3.0.0-alpha-1 when using DefaultLdapRealm. Attackers can exploit this by directly concatenating user-supplied username input into the LDAP DN template without [truncated]
CVE-2026-25700 is a HIGH severity vulnerability in Apache Answer, with a CVSS score of 7.2. The vulnerability is caused by improper restriction of security token assignment, allowing previously issued administrative tokens to remain valid even after an administrator account was suspended, deleted, or deactivated. This issue affects Apache Answer through version 2.0.0. Users are recommended to upgrade to v [truncated]
CVE-2026-34905 is a MEDIUM-severity vulnerability in Apache Answer, a question-and-answer platform. The issue affects Apache Answer through version 2.0.0 and allows authenticated users to discover and access unlisted questions, their answers, comments, and revision history due to insufficient access restrictions on direct API endpoints for unlisted questions. The CVSS score for this vulnerability is 6.5.
CVE-2026-34033 is a MEDIUM severity vulnerability in Apache Answer through 2.0.0, allowing authenticated users to inject arbitrary HTML into emails sent to other users due to improper neutralization of script-related HTML tags. Users are recommended to upgrade to version 2.0.1 to fix the issue.
CVE-2026-34031 is a Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
CVE-2026-33582 is a Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer through version 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
CVE-2026-25699 is a MEDIUM severity vulnerability in Apache Answer through 2.0.0. The issue arises from timeline-related APIs lacking proper authorization checks, which allowed regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. The vulnerability has a CVSS score of 6.1 and was pub [truncated]
CVE-2026-25688 is a MEDIUM-severity vulnerability in Apache Answer, a Q&A platform. The issue, classified as CWE-87, involves improper neutralization of alternate XSS syntax. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. This vulnerability affects Apache Answer through version 2.0.0 and is fixed [truncated]
A Use After Free vulnerability was discovered in the Apache HTTP Server module mod_http2 (CVE-2026-48913). The vulnerability occurs when file handles are already exhausted. This issue affects Apache HTTP Server versions from 2.4.55 through 2.4.67, with a CVSS score of 7.3 and a severity rating of HIGH.
A Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
CVE-2026-44186 is a HIGH severity vulnerability in Apache HTTP Server's mod_proxy_ftp module. The issue is caused by an infinite loop with an unreachable exit condition, which can be triggered by an attacker-controlled backend FTP server. The vulnerability affects Apache HTTP Server versions from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue. The CVSS scor [truncated]
CVE-2026-44185 is a Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server. This issue affects Apache HTTP Server versions from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue. The CVSS score for this vulnerability is 7.3, with a severity rating of HIGH.
CVE-2026-44119 is an Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier. This vulnerability allows local .htaccess authors to read files with the privileges of the httpd user. The issue affects Apache HTTP Server versions from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue. The CVSS score for this vulnerability is 5.5, with [truncated]
CVE-2026-43951 is a MEDIUM-severity vulnerability in Apache HTTP Server versions from 2.4.0 through 2.4.67. The vulnerability is caused by an out-of-bounds read issue when using mod_headers and mod_mime with multiple response languages.
CVE-2026-42536 is a Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content. This issue affects Apache HTTP Server versions from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
CVE-2026-34356 is a Heap-based Buffer Overflow vulnerability in Apache HTTP Server. The vulnerability occurs with malicious backend servers and ProxyPassReverseCookie*. The issue affects Apache HTTP Server versions from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue. The CVSS score for this vulnerability is 7.5, and the severity is classified as HIGH.
CVE-2026-34355 is a HIGH severity vulnerability in Apache HTTP Server 2.4.67 and earlier. The vulnerability is caused by a buffer overflow in mod_proxy_html, which allows an attack by an untrusted backend. The CVSS score is 7.5. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
CVE-2026-29167 is a Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue. The CVSS score for this vulnerability is 9.8, indicating a CRITICAL severity.
CVE-2026-50076 is a Deserialization of Untrusted Data vulnerability in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms. This vulnerability allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke classpath-present readResolve/readExternal hooks via crafted Fory serialized data. The CVSS score for this vulner [truncated]
CVE-2026-44618 is a vulnerability in Apache CXF's WS-Transfer module due to insecure XML parser configuration, potentially allowing XXE attacks. Users are advised to upgrade to versions 4.2.1, 4.1.6, or 3.6.11 for a fix. This issue arises from an insecure XML parser configuration, which may enable attackers to perform XXE attacks. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM sever [truncated]
CVE-2026-45434 is a critical Apache OFBiz vulnerability affecting versions before 24.09.06. The issue is described as an improper authentication flaw in password-change logic that can lead to remote code execution. Because the CVSS 3.1 score is 9.8 and the vector indicates network exploitation without privileges or user interaction, affected OFBiz instances should be treated as urgent patch candidates.
CVE-2026-31909 is an information disclosure issue in Apache OFBiz affecting versions before 24.09.06. The supplied record points to CWE-200 and recommends upgrading to 24.09.06 to fix the issue.
CVE-2026-31378 is an Apache OFBiz vulnerability described as improper input validation. According to the supplied source corpus, it affects Apache OFBiz versions before 24.09.06, and Apache recommends upgrading to 24.09.06 to fix the issue. The available record does not provide a CVSS score or additional exploitation details, so defenders should treat this as a version-level remediation item and verify ex [truncated]
CVE-2026-29226 is a Server-Side Request Forgery (SSRF) vulnerability affecting Apache OFBiz before 24.09.06. The issue is associated with Content component operations and was published on 2026-05-19. Apache recommends upgrading to version 24.09.06, which fixes the issue.
CVE-2026-29220 is a path traversal issue in Apache OFBiz affecting versions before 24.09.06. Apache recommends upgrading to 24.09.06, which fixes the issue. The NVD record maps the weakness to CWE-22.