PatchSiren

Apache CVE debriefs · Page 5

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Apache CVE published 2026-05-08

CVE-2026-39816

CVE-2026-39816 is a high-severity authorization issue in Apache NiFi’s optional TinkerpopClientService. In affected NiFi versions, the service can be configured without the Restricted annotation that should require Execute Code permission. In environments using fine-grained authorization, that means a user who lacks Execute Code permission may still be able to configure the service if the optional graph-s [truncated]

CRITICAL Apache CVE published 2026-05-08

CVE-2026-25199

CVE-2026-25199 is a critical Apache CloudStack flaw in the Proxmox extension that can let a non-privileged tenant user gain unauthorized access to another tenants instance. The issue stems from use of a user-editable instance detail, proxmox_vmid, to bind CloudStack instances to Proxmox virtual machines. Because that value is not restricted or validated against tenant ownership and Proxmox VM IDs are pre [truncated]

HIGH Apache CVE published 2026-05-08

CVE-2026-25077

CVE-2026-25077 affects Apache CloudStack deployments that use the KVM hypervisor. According to the vendor advisory and NVD record, account users can register templates that are downloaded directly to primary storage for instance deployment; missing file name sanitization can then allow malicious templates to execute arbitrary code on KVM hosts. Apache says upgrading to 4.20.3.0, 4.22.0.1, or later fixes the issue.

MEDIUM Apache CVE published 2026-05-08

CVE-2025-69233

CVE-2025-69233 affects Apache CloudStack and was published on 2026-05-08, with a modification on 2026-05-09. The issue is a set of time-of-check time-of-use race conditions plus missing validations in resource count check and increment logic. In practice, that can let users exceed account or domain allocation limits, which may degrade infrastructure resources and create denial-of-service conditions. Apach [truncated]

HIGH Apache CVE published 2026-05-08

CVE-2025-66467

CVE-2025-66467 is a high-severity Apache CloudStack issue where MinIO policy cleanup does not occur when a bucket is deleted. If another user later creates a bucket with the same name, the prior owner can keep using previously issued access and secret keys to reach the new bucket with unauthorized read and write access. Apache recommends upgrading to 4.20.3.0 or 4.22.0.1, or later.

CRITICAL Apache CVE published 2026-05-05

CVE-2026-28780

CVE-2026-28780 is a critical vulnerability in Apache HTTP Server's mod_proxy_ajp. A malicious AJP server can send a crafted AJP message to cause a heap-based buffer overflow, allowing the attacker to write 4 controlled bytes after the buffer end. This issue affects Apache HTTP Server through version 2.4.66 and is fixed in version 2.4.67. The vulnerability has a CVSS score of 9.8 and is considered critical [truncated]

HIGH Apache CVE published 2026-05-05

CVE-2026-43869

CVE-2026-43869 is an Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. The issue affects Apache Thrift versions before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. The vulnerability has a CVSS score of 7.3 and is classified as HIGH severity. It was published on May 5, 2026, and modified on July 1, 2026.

HIGH Apache CVE published 2026-04-28

CVE-2025-48431

CVE-2025-48431 is a Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. The issue affects Apache Thrift versions before 0.23.0. Specially crafted requests can crash an c_glib-based Thrift server with a clean but fatal 'free(): invalid pointer' error message. Users are recommended to upgrade to version 0.23.0, which fixes the issue. The CVSS score for this vulnera [truncated]

CRITICAL Apache CVE published 2026-04-27

CVE-2026-33453

CVE-2026-33453 is a critical vulnerability in Apache Camel's camel-coap component. The vulnerability allows for remote code execution via Camel message header injection when routes forward CoAP requests to header-sensitive producers. The issue arises from the component mapping incoming CoAP request URI query parameters directly into Camel Exchange In message headers without applying any HeaderFilterStrate [truncated]

HIGH Apache CVE published 2026-04-27

CVE-2026-27172

CVE-2026-27172 is a deserialization vulnerability in the ConsulRegistry component of Apache Camel. The issue arises from the ConsulRegistry and its inner ConsulRegistryUtils.deserialize method reading Java-serialized values from the Consul KV store and passing them to ObjectInputStream.readObject() without configuring an ObjectInputFilter. This allows an attacker who can write to the Consul KV store to in [truncated]

HIGH Apache CVE published 2026-04-27

CVE-2026-40022

CVE-2026-40022 is a high-severity authentication bypass vulnerability in Apache Camel, a popular open-source integration framework. The issue arises when authentication is enabled on the Apache Camel embedded HTTP server or embedded management server, and a non-root context path is configured. In such cases, the BasicAuthenticationConfigurer and JWTAuthenticationConfigurer classes derive the authenticatio [truncated]

CRITICAL Apache CVE published 2026-04-27

CVE-2026-40860

CVE-2026-40860 is a remote code execution vulnerability in Apache Camel, a popular open-source integration framework. The vulnerability exists in the JmsBinding class, which deserializes the payload of incoming JMS ObjectMessage values without applying any ObjectInputFilter, class allowlist, or class denylist. This allows an attacker to publish a crafted ObjectMessage to a queue or topic consumed by a Cam [truncated]

HIGH Apache CVE published 2026-04-27

CVE-2026-40473

CVE-2026-40473 is a remote code execution vulnerability in Apache Camel's camel-mina component. The MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. This allows an attacker to send a crafted serialized Java object over the network to the MINA consumer port, triggering arbitrary code e [truncated]

CRITICAL Apache CVE published 2026-04-20

CVE-2026-33557

A critical security vulnerability has been identified in Apache Kafka, affecting versions 4.1.0 and 4.1.1. The vulnerability is due to the default configuration of the `sasl.oauthbearer.jwt.validator.class` property, which allows any JWT token to be accepted without validation. This could allow an attacker to generate a JWT token with any issuer and `preferred_username` set to any user, potentially leadin [truncated]

MEDIUM Apache CVE published 2026-04-18

CVE-2026-40948

CVE-2026-40948 describes an authentication-flow weakness in apache-airflow-providers-keycloak where the Keycloak login / callback handling did not generate or validate the OAuth 2.0 state parameter and did not use PKCE. In the documented scenario, an attacker with a Keycloak account in the same realm could steer a victim’s browser into a crafted callback URL and cause the victim to end up logged into the [truncated]

Known exploited Apache CVE published 2026-04-16

CVE-2026-34197

CVE-2026-34197 is a publicly listed Apache ActiveMQ flaw described as an improper input validation vulnerability and added to CISA’s Known Exploited Vulnerabilities catalog on 2026-04-16. Because CISA has designated it as actively exploited, defenders should treat exposure as urgent and follow Apache’s remediation guidance, with special attention to cloud-service guidance where applicable.

MEDIUM Apache CVE published 2026-04-10

CVE-2026-34481

Apache Log4j's JsonTemplateLayout, in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN, Infinity, or -Infinity), which are prohibited by RFC 8259. This may cause downstream log processing systems to reject or fail to index affected records. The vulnerability affects users of Apache Log4j who use JsonTemplateLayout and log MapMe [truncated]

HIGH Apache CVE published 2026-04-09

CVE-2026-29146

CVE-2026-29146 is a Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat versions from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9.0.115, from 8.5.38 through 8.5.100, and from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53, and 9.0.116, which fixes the issu [truncated]

HIGH Apache CVE published 2026-04-07

CVE-2026-35554

A race condition in Apache Kafka's Java producer client's buffer pool management can cause messages to be silently delivered to incorrect topics. This issue affects Apache Kafka versions ≤ 3.9.1, ≤ 4.0.1, and ≤ 4.1.1. Users are advised to upgrade to 3.9.2, 4.0.2, 4.1.2, 4.2.0, or later. The vulnerability, known as CVE-2026-35554, has a CVSS score of 8.7 and is considered high severity. It can lead to data [truncated]

LOW Apache CVE published 2026-03-24

CVE-2026-32642

CVE-2026-32642 is an Incorrect Authorization (CWE-863) vulnerability in Apache Artemis and Apache ActiveMQ Artemis. The vulnerability occurs when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authenticated user who has the 'createDurableQueue' permission but does not have the 'createAddress' permission and addres [truncated]

MEDIUM Apache CVE published 2026-03-10

CVE-2026-23907

CVE-2026-23907 is a path traversal vulnerability in the ExtractEmbeddedFiles example of Apache PDFBox, affecting versions 2.0.24 through 2.0.35 and 3.0.0 through 3.0.6. The vulnerability allows attackers to access files outside the intended directory by manipulating the filename obtained from PDComplexFileSpecification.getFilename(). Users who have copied this example into their production code should rev [truncated]

MEDIUM Apache CVE published 2026-03-03

CVE-2025-59060

Apache Ranger versions <= 2.7.0 have a hostname verification bypass issue in Apache Ranger NiFiRegistryClient. This issue allows for hostname verification bypass, which can lead to security risks. Users are recommended to upgrade to version 2.8.0, which fixes this issue. The vulnerability affects operators, platform administrators, vulnerability management teams, and security teams who use Apache Ranger. [truncated]

HIGH Apache CVE published 2026-02-23

CVE-2026-25747

CVE-2026-25747 is a Deserialization of Untrusted Data vulnerability in the Apache Camel LevelDB component. The vulnerability exists in the DefaultLevelDBSerializer class, which deserializes data from the LevelDB aggregation repository using java.io.ObjectInputStream without proper filtering or class-loading restrictions. This allows an attacker who can write to the LevelDB database files to inject a craft [truncated]

HIGH Apache CVE published 2026-02-17

CVE-2026-24734

CVE-2026-24734 is an Improper Input Validation vulnerability in Apache Tomcat Native and Apache Tomcat. When using an OCSP responder, Tomcat Native did not complete verification or freshness checks on the OCSP response, which could allow certificate revocation to be bypassed. This issue affects multiple versions of Apache Tomcat Native and Apache Tomcat. Users are recommended to upgrade to fixed versions [truncated]

MEDIUM Apache CVE published 2026-02-09

CVE-2026-23903

CVE-2026-23903 is an Authentication Bypass by Alternate Name vulnerability in Apache Shiro before version 2.0.7. This issue affects static files served from case-insensitive filesystems, allowing access by varying filename case in requests. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users are recommended to upgrade to version 2.0.7 or configure case insensitivity param [truncated]

Known exploited Apache CVE published 2025-05-01

CVE-2024-38475

CVE-2024-38475 is a known-exploited vulnerability affecting Apache HTTP Server. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-05-01, which means defenders should treat it as a high-priority remediation item and follow vendor mitigation guidance.

Known exploited Apache CVE published 2025-04-01

CVE-2025-24813

CVE-2025-24813 is an Apache Tomcat path equivalence vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-04-01, indicating it should be treated as a high-priority defensive item. The available official guidance is to apply vendor mitigations, follow applicable BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable.

Known exploited Apache CVE published 2025-02-04

CVE-2024-45195

CVE-2024-45195 is an Apache OFBiz forced browsing vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-02-04. Because CISA identified it as known exploited, organizations using OFBiz should treat it as an active defensive priority and follow vendor guidance quickly. CISA’s KEV entry directs organizations to apply mitigations per vendor instructions or discontinue use of the [truncated]

Known exploited Apache CVE published 2024-09-18

CVE-2024-27348

CVE-2024-27348 is an Apache HugeGraph-Server improper access control issue that CISA added to its Known Exploited Vulnerabilities catalog on 2024-09-18. Because it is listed in KEV, defenders should treat it as a priority issue for exposed HugeGraph-Server deployments and any downstream products that incorporate it. CISA’s required action is to apply vendor mitigations or discontinue use if mitigations ar [truncated]

Known exploited Apache CVE published 2024-08-27

CVE-2024-38856

CVE-2024-38856 is an incorrect authorization issue in Apache OFBiz. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-27, which makes it a high-priority issue for any organization running OFBiz. The supplied records do not include a CVSS score or fixed-version details, so defenders should rely on vendor guidance and the KEV-required action immediately.