Skip to content
VulniPulse

Apache Software Foundation Security Advisories & CVEs

362 advisories tracked · ASF Security (security@apache.org CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Apache CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Apache device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Apache's recent advisories.

Official source

ASF Security (security@apache.org CNA) via NVD

The Apache Software Foundation is its own CVE Numbering Authority: every Apache project CVE (HTTP Server, Tomcat, ActiveMQ, Struts, Kafka, Airflow, OFBiz, Solr and 300+ more) is published by security@apache.org and announced on the projects' mailing lists. VulniPulse ingests the CNA feed from NVD filtered to security@apache.org — official, machine-readable, with affected/fixed versions embedded in each description. Per-project security pages (httpd.apache.org/security, tomcat.apache.org/security-XX.html) carry the vendor detail.

Latest Apache advisories

High7.0Apache

High [CVE-2026-102795 +1] Improper Access Control vulnerability in Apache Traffic Server

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. This CVE supersedes CVE-2026-41920, whose record listed the affected 9.x versions as 9.0.0 through 9.1.14 and the fixed version as 9.1.15. All 9.2.x releases before 9.2.15 are affected.

CVE-2026-102795CVE-2026-41920
Infra & Gateways
Oct 2, 2026
High7.1Apache Updated

High [CVE-2026-61374] Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-61374
Unclassified
Oct 2, 2026
High8.7Apache Updated

High [CVE-2026-63772] Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift go bindings

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift go bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-63772
Unclassified
Oct 2, 2026
High8.2Apache Updated

High [CVE-2026-66055] Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift C++, Java, Go, netstd, Python and Delphi bindings

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift C++, Java, Go, netstd, Python and Delphi bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-66055
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-66081] Access of Uninitialized Pointer vulnerability in Apache Thrift c_glib bindings

Access of Uninitialized Pointer vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-66081
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-66837] Stack-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in Apache Thrift php bindings

Stack-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in Apache Thrift php bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-66837
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-66858] The protocol skip routine in several Apache Thrift bindings did not apply the binding's recursion limit, so a message that nests unknown fields deeply enough can exhaust the stack

The protocol skip routine in several Apache Thrift bindings did not apply the binding's recursion limit, so a message that nests unknown fields deeply enough can exhaust the stack. Affected: the Python C++ accelerator (the pure-Python protocols are not affected), the PHP library and its thrift_protocol extension, and the Perl, Lua, Smalltalk and OCaml libraries. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-66858
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-66859] NULL Pointer Dereference, Use of Uninitialized Variable vulnerability in Apache Thrift c_glib bindings

NULL Pointer Dereference, Use of Uninitialized Variable vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-66859
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-83663] Uncontrolled Recursion vulnerability in Apache Thrift go bindings

Uncontrolled Recursion vulnerability in Apache Thrift go bindings. Both Go transports satisfy a read out of a buffered frame and, when that frame yields no payload bytes, read the next frame and call `Read` again instead of looping. A peer produces such a frame for 4 bytes in `TFramedTransport` (a declared size of zero) or 18 bytes in `THeaderTransport` (a header block that fills the frame), so nothing bounds the depth. The Go stack limit is reached as a `fatal error`, which `recover()` cannot catch, so the whole process dies. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-83663
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-83745] Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift nodejs and D lang bindings

Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift nodejs and D lang bindings. Both bindings' WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the bytes have arrived. A single ~14-byte frame therefore commits as much memory as it cares to declare -- measured at 513 MiB against the Node.js server and 2 GiB against the D transport -- and in the Node.js case the connection is left open afterwards, so the frame can simply be sent again. This issue affects Apache Thrift before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-83745
Unclassified
Oct 2, 2026
High8.2Apache

High [CVE-2026-85476] Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift c_glib bindings

Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-85476
Unclassified
Oct 2, 2026
High8.2Apache

High [CVE-2026-96289] Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings

Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-96289
Unclassified
Oct 2, 2026
High8.2Apache

High [CVE-2026-96287] Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings

Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-96287
Unclassified
Oct 2, 2026
High8.2Apache

High [CVE-2026-96286] Uncaught exception vulnerability in Apache Thrift Perl bindings

Uncaught exception vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-96286
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-96277] Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings

Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-96277
Unclassified
Oct 2, 2026
High8.7Apache

High [CVE-2026-94658] Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings

Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94658
Unclassified
Oct 2, 2026
High8.2Apache

High [CVE-2026-94657] Allocation of resources without limits or throttling vulnerability in Apache Thrift JavaME bindings

Allocation of resources without limits or throttling vulnerability in Apache Thrift JavaME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94657
Unclassified
Oct 2, 2026
High8.2Apache

High [CVE-2026-94656] Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings

Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94656
Unclassified
Oct 2, 2026
High8.2Apache

High [CVE-2026-94655] Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings

Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94655
Unclassified
Oct 2, 2026
High8.2Apache

High [CVE-2026-94654] Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift python bindings

Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94654
Unclassified
Oct 2, 2026

← All vendors