Skip to content
VulniPulse

Apache Software Foundation Security Advisories & CVEs

196 advisories tracked · ASF Security (security@apache.org CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Apache CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Apache device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Apache's recent advisories.

Official source

ASF Security (security@apache.org CNA) via NVD

The Apache Software Foundation is its own CVE Numbering Authority: every Apache project CVE (HTTP Server, Tomcat, ActiveMQ, Struts, Kafka, Airflow, OFBiz, Solr and 300+ more) is published by security@apache.org and announced on the projects' mailing lists. VulniPulse ingests the CNA feed from NVD filtered to security@apache.org — official, machine-readable, with affected/fixed versions embedded in each description. Per-project security pages (httpd.apache.org/security, tomcat.apache.org/security-XX.html) carry the vendor detail.

Latest Apache advisories

High7.5Apache

High [CVE-2026-66273] Apache Qpid Proton-J: pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.

CVE-2026-66273
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-67588] Apache Qpid ProtonJ2: pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.

CVE-2026-67588
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-67465] Apache Qpid Proton-Dotnet: pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.

CVE-2026-67465
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-68074] Apache Qpid Broker-J: pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.

CVE-2026-68074
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-66257] Apache Qpid Proton-J: pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.

CVE-2026-66257
Unclassified
Aug 5, 2026
High8.8Apache

High [CVE-2026-68981] Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter

Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which relocates response compression to Jetty Server and disables decompression of gzip-encoded HTTP requests.

CVE-2026-68981
NiFi
Aug 3, 2026
High7.7Apache

High [CVE-2026-62354] Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values

Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined component validation methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying Parameter Context configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, requiring write access to submit Parameter Context validation requests.

CVE-2026-62354
NiFi
Aug 3, 2026
High7.5Apache

High [CVE-2026-61372] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena Fuseki: through 6.1.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue.

CVE-2026-61372
Unclassified
Aug 3, 2026
High8.1Apache

High [CVE-2025-66518 +1] Apache Kyuubi Server: The security fix for CVE-2025-66518 is incomplete

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. This issue affects Apache Kyuubi: from 1.6.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which fixes the issue.

CVE-2025-66518CVE-2026-62391
Unclassified
Jul 31, 2026
High7.5Apache

High [CVE-2026-28814] Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables

Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables. Users are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue.

CVE-2026-28814
Unclassified
Jul 30, 2026
High8.8Apache

High [CVE-2026-28813] Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities

Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.4, which fixes this issue.

CVE-2026-28813
Unclassified
Jul 30, 2026
High7.5Apache

High [CVE-2026-28811] Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3

Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this issue.

CVE-2026-28811
Unclassified
Jul 30, 2026
High8.8Apache

High [CVE-2026-50622] Description: Missing Authorization in Apache Atlas

Missing Authorization in Apache Atlas. Affect Version: This issue affects Apache Atlas: from 0.8 through 2.5.0.

CVE-2026-50622
Unclassified
Jul 29, 2026
High7.3Apache

High [CVE-2026-23904] Apache Kyuubi: Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination

Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, resulting in SSRF or open-proxy behavior. This issue affects Apache Kyuubi: from 1.8.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which disables the proxy by default. To restore proxied Engine UI, set kyuubi.frontend.rest.engine.ui.proxy.enabled=true and configure allowed target hosts with kyuubi.frontend.rest.engine.ui.proxy.hosts.

CVE-2026-23904
Unclassified
Jul 29, 2026
High8.2Apache

High [CVE-2026-58189] Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification

Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58189
Infra & Gateways
Jul 29, 2026
High8.4Apache

High [CVE-2026-58188] Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors

Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58188
Infra & Gateways
Jul 29, 2026
High8.2Apache

High [CVE-2026-58186] The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses

The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58186
Infra & Gateways
Jul 29, 2026
High8.2Apache

High [CVE-2026-58185] The Apache Traffic Server intercept plugin has a use-after-free

The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58185
Infra & Gateways
Jul 29, 2026
High8.3Apache

High [CVE-2026-58184] The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching

The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58184
Infra & Gateways
Jul 29, 2026
High8.2Apache

High [CVE-2026-58183] The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input

The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVE-2026-58183
Infra & Gateways
Jul 29, 2026

← All vendors