Skip to content
VulniPulse

Apache Software Foundation Security Advisories & CVEs

802 advisories tracked · ASF Security (security@apache.org CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Apache CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Apache device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Apache's recent advisories.

Official source

ASF Security (security@apache.org CNA) via NVD

The Apache Software Foundation is its own CVE Numbering Authority: every Apache project CVE (HTTP Server, Tomcat, ActiveMQ, Struts, Kafka, Airflow, OFBiz, Solr and 300+ more) is published by security@apache.org and announced on the projects' mailing lists. VulniPulse ingests the CNA feed from NVD filtered to security@apache.org — official, machine-readable, with affected/fixed versions embedded in each description. Per-project security pages (httpd.apache.org/security, tomcat.apache.org/security-XX.html) carry the vendor detail.

Latest Apache advisories

High8.7Apache

High [CVE-2026-96277] Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings

Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-96277
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-94658] Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings

Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94658
Unclassified
Oct 2, 2026
High8.2Apache

High [CVE-2026-94657] Allocation of resources without limits or throttling vulnerability in Apache Thrift JavaME bindings

Allocation of resources without limits or throttling vulnerability in Apache Thrift JavaME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94657
Unclassified
Oct 2, 2026
High8.2Apache

High [CVE-2026-94656] Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings

Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94656
Unclassified
Oct 2, 2026
High8.2Apache

High [CVE-2026-94655] Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings

Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94655
Unclassified
Oct 2, 2026
High8.2Apache

High [CVE-2026-94654] Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift python bindings

Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94654
Unclassified
Oct 2, 2026
High8.2Apache Updated

High [CVE-2026-94653] Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings

Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94653
Unclassified
Oct 2, 2026
High8.2Apache Updated

High [CVE-2026-94648] Allocation of resources without limits or throttling vulnerability in Apache Thrift dart bindings

Allocation of resources without limits or throttling vulnerability in Apache Thrift dart bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94648
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-94646] Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift nodejs bindings

Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94646
Unclassified
Oct 2, 2026
High8.2Apache Updated

High [CVE-2026-94637] Improper handling of highly compressed data (data amplification) vulnerability in Apache Thrift Go bindings

Improper handling of highly compressed data (data amplification) vulnerability in Apache Thrift Go bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94637
Unclassified
Oct 2, 2026
High8.2Apache

High [CVE-2026-94636] Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arguments, Improper validation of specified quantity in input vulnerability in Apache Thrift py bindings

Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arguments, Improper validation of specified quantity in input vulnerability in Apache Thrift py bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94636
Unclassified
Oct 2, 2026
High8.2Apache

High [CVE-2026-90440] Uncaught exception, improper handling of exceptional conditions, improper resource shutdown vulnerability in Apache Thrift D thrift.server.nonblocking.TNonblockingServer

Uncaught exception, improper handling of exceptional conditions, improper resource shutdown vulnerability in Apache Thrift D thrift.server.nonblocking.TNonblockingServer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-90440
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-87117] NULL pointer dereference vulnerability in Apache Thrift PHP bindings

NULL pointer dereference vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-87117
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-86537] Uncaught exception, Loop with unreachable exit condition ('infinite loop'), Integer underflow (wrap or wraparound) vulnerability in Apache Thrift D language bindings

Uncaught exception, Loop with unreachable exit condition ('infinite loop'), Integer underflow (wrap or wraparound) vulnerability in Apache Thrift D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-86537
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-86535] Loop with unreachable exit condition ('infinite loop'), Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift NodeJS bindings with TJSONProtocol

Loop with unreachable exit condition ('infinite loop'), Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift NodeJS bindings with TJSONProtocol. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-86535
Unclassified
Oct 2, 2026
High8.2Apache

High [CVE-2026-82459] Integer underflow (wrap or wraparound), Out-of-bounds write vulnerability in Apache Thrift C++ 32 bit THeaderTransport

Integer underflow (wrap or wraparound), Out-of-bounds write vulnerability in Apache Thrift C++ 32 bit THeaderTransport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-82459
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-82458] Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerability in Apache Thrift Go, netstd, OCaml, Erlang, JavaME, Rust, C++, Java, Kotlin and D language bindings

Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerability in Apache Thrift Go, netstd, OCaml, Erlang, JavaME, Rust, C++, Java, Kotlin and D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-82458
Unclassified
Oct 2, 2026
High8.2Apache

High [CVE-2026-96288] Uncontrolled Recursion, Allocation of resources without limits or throttling vulnerability in Apache Thrift Erlang bindings

Uncontrolled Recursion, Allocation of resources without limits or throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-96288
Unclassified
Oct 2, 2026
High8.2Apache

High [CVE-2026-96292] Inefficient regular expression complexity, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings

Inefficient regular expression complexity, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-96292
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-96294] Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings

Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-96294
Unclassified
Oct 2, 2026

← All vendors