Skip to content
VulniPulse

Apache Software Foundation Security Advisories & CVEs

362 advisories tracked · ASF Security (security@apache.org CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Apache CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Apache device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Apache's recent advisories.

Official source

ASF Security (security@apache.org CNA) via NVD

The Apache Software Foundation is its own CVE Numbering Authority: every Apache project CVE (HTTP Server, Tomcat, ActiveMQ, Struts, Kafka, Airflow, OFBiz, Solr and 300+ more) is published by security@apache.org and announced on the projects' mailing lists. VulniPulse ingests the CNA feed from NVD filtered to security@apache.org — official, machine-readable, with affected/fixed versions embedded in each description. Per-project security pages (httpd.apache.org/security, tomcat.apache.org/security-XX.html) carry the vendor detail.

Latest Apache advisories

High8.2Apache

High [CVE-2026-94651] improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings

improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94651
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-85493] Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings

Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-85493
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-85494] Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP and D language bindings

Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP and D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-85494
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-91137] Improper validation of specified quantity in input, Allocation of resources without limits or throttling, Excessive Iteration vulnerability in Apache Thrift PHP bindings

Improper validation of specified quantity in input, Allocation of resources without limits or throttling, Excessive Iteration vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-91137
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-93925] Stack-based buffer overflow, Incorrect bitwise shift of integer vulnerability in Apache Thrift C++ THeaderProtocol

Stack-based buffer overflow, Incorrect bitwise shift of integer vulnerability in Apache Thrift C++ THeaderProtocol. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-93925
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-93926] Missing release of memory after effective lifetime, Missing release of resource after effective lifetime vulnerability in Apache Thrift THeaderTransport

Missing release of memory after effective lifetime, Missing release of resource after effective lifetime vulnerability in Apache Thrift THeaderTransport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-93926
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-94633] Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Dart bindings

Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Dart bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94633
Unclassified
Oct 2, 2026
High8.2Apache

High [CVE-2026-94634] Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python bindings

Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94634
Unclassified
Oct 2, 2026
High8.2Apache Updated

High [CVE-2026-61373 +1] Apache Thrift: Java `TSaslNonblockingServer`: residual of CVE-2026-61373 (thread-death black hole + no cross-connection budget)

improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught exception vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-61373CVE-2026-94639
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-94635] Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Lua bindings

Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94635
Unclassified
Oct 2, 2026
High7.5Apache

High [CVE-2026-63686] NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails

A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

CVE-2026-63686
HTTP Server
Oct 1, 2026
High8.8Apache

High [CVE-2026-93546] Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.

CVE-2026-93546
HTTP Server
Oct 1, 2026
High7.3Apache

High [CVE-2026-73637] Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0

Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

CVE-2026-73637
HTTP Server
Oct 1, 2026
High8.1Apache

High [CVE-2026-73636] Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

CVE-2026-73636
HTTP Server
Oct 1, 2026
High7.5Apache

High [CVE-2026-63718] Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68.

CVE-2026-63718
HTTP Server
Oct 1, 2026
High7.5Apache

High [CVE-2026-63292] Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default

Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

CVE-2026-63292
HTTP Server
Oct 1, 2026
High7.5Apache

High [CVE-2026-63045] Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response

Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

CVE-2026-63045
HTTP Server
Oct 1, 2026
High7.5Apache

High [CVE-2026-59685] Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded

Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

CVE-2026-59685
HTTP Server
Oct 1, 2026
High7.5Apache

High [CVE-2026-56449] Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies

Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

CVE-2026-56449
HTTP Server
Oct 1, 2026
High7.5Apache

High [CVE-2026-56153] Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite

Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

CVE-2026-56153
HTTP Server
Oct 1, 2026

← All vendors