Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.1Apache

High [CVE-2026-40563] Apache Atlas Apache: Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL…

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings. Attacker can alter Gremlin traversal logic within grammar-allowed characters to access unintended data Affect Version: This issue affects Apache Atlas: from 0.8 through 2.4.0. atlas.dsl.executor.traversal=false

CVE-2026-40563
Unclassified
May 4, 2026
High7.5Apache

High [CVE-2026-29169] NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may

A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.

CVE-2026-29169
HTTP Server
May 4, 2026
High8.8Apache

High [CVE-2026-23918] Apache HTTP Server: http2: double free and possible RCE on early reset

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVE-2026-23918
HTTP Server
May 4, 2026
High7.5Apache

High [CVE-2026-34059] Apache HTTP Server: Buffer Over-read vulnerability in Apache HTTP Server.

Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVE-2026-34059
HTTP Server
May 4, 2026
Medium6.5Apache

Medium [CVE-2026-33523] HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers

HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVE-2026-33523
HTTP Server
May 4, 2026
Medium5.3Apache

Medium [CVE-2026-33007] NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier

A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

CVE-2026-33007
HTTP Server
May 4, 2026
Medium4.8Apache

Medium [CVE-2026-33006] timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker

A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

CVE-2026-33006
HTTP Server
May 4, 2026
Medium5.3Apache

Medium [CVE-2026-34032] Apache HTTP Server: Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.

Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVE-2026-34032
HTTP Server
May 4, 2026
Medium5.3Apache

Medium [CVE-2026-33857] Apache HTTP Server: Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server.

Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVE-2026-33857
HTTP Server
May 4, 2026
Critical9.8Apache

Critical [CVE-2024-52046 +2] Apache MINA AbstractIoBuffer: The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches.

The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed. Affected versions are Apache MINA 2.1.0 <= 2.1.11, and 2.2.0 <= 2.2.6. The problem is resolved in Apache MINA 2.1.12, and 2.2.7 by applying the classname allowlist earlier. Affected are applications using Apache MINA that call IoBuffer.getObject(). Applications using Apache MINA are advised to upgrade

CVE-2024-52046CVE-2026-41409CVE-2026-42778
Unclassified
May 1, 2026
Medium5.9Apache

Medium [CVE-2026-41016] Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate…

Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performed on the TLS upgrade. A man-in-the-middle between the Airflow worker and the SMTP server could present a self-signed certificate, complete the STARTTLS upgrade, and capture the SMTP credentials sent during the subsequent `login()` call. Users are advised to upgrade to the `apache-airflow-providers-smtp` version that contains the fix.

CVE-2026-41016
Airflow
Apr 30, 2026
High8.7Apache

High [CVE-2026-41636] Apache Thrift Node: Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0.

Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

CVE-2026-41636
Unclassified
Apr 28, 2026
High7.3Apache

High [CVE-2026-41605] Apache Thrift: Swift Compact Protocol integer overflow

Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

CVE-2026-41605
Unclassified
Apr 28, 2026
High8.2Apache

High [CVE-2026-41604] Apache Thrift: Swift Range crash in skip

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

CVE-2026-41604
Unclassified
Apr 28, 2026
High7.4Apache

High [CVE-2026-41603] Apache Thrift: Java TSSLTransportFactory hostname verification

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

CVE-2026-41603
Unclassified
Apr 28, 2026
High7.5Apache

High [CVE-2026-41602] Apache Thrift: Go TFramedTransport uint32 overflow

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

CVE-2026-41602
Unclassified
Apr 28, 2026
High7.5Apache

High [CVE-2025-48431] Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error.

Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Specially crafted requests can crash an c_glib-based Thrift server with a clean but fatal "free(): invalid pointer" error message.

CVE-2025-48431
Unclassified
Apr 28, 2026
Medium6.5Apache

Medium [CVE-2026-41607] Apache Thrift: C++ JSON OOB read

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

CVE-2026-41607
Unclassified
Apr 28, 2026
Medium5.3Apache

Medium [CVE-2026-41606] Apache Thrift: c_glib dispatch stack overflow

Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

CVE-2026-41606
Unclassified
Apr 28, 2026
Critical10.0Apache

Critical [CVE-2026-33453] Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's camel-coap component is vulnerable to Camel message header injection, leading to remote code execution when routes forward CoAP requests to header-sensitive producers (e.g. camel-exec) The camel-coap component maps incoming CoAP request URI query parameters directly into Camel Exchange In message headers without applying any HeaderFilterStrategy. Specifically, CamelCoapResource.handleRequest() iterates over OptionSet.getUriQuery() and calls camelExchange.getIn().setHeader(...) for every query parameter. CoAPEndpoint extends DefaultEndpoint rather than DefaultHeaderFilterStrategyEndpoint, and CoAPComponent does not implement HeaderFilterStrategyComponent; the component contains no references to HeaderFilterStrategy at all. As a result, an unauthenticated attacker who can send a single CoAP UDP packet to a Camel route consuming from coap:// can inject arbitrary Camel internal headers (those prefixed with Camel*) into the Exchange. When the route delivers the message to a header-sensitive producer such as camel-exec, camel-sql, camel-bean, camel-file, or template components (camel-freemarker, camel-velocity), the injected headers can alter the producer's behavior.

CVE-2026-33453
Messaging
Apr 27, 2026