Skip to content
VulniPulse

Apache Software Foundation Security Advisories & CVEs

230 advisories tracked · ASF Security (security@apache.org CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Apache CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Apache device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Apache's recent advisories.

Official source

ASF Security (security@apache.org CNA) via NVD

The Apache Software Foundation is its own CVE Numbering Authority: every Apache project CVE (HTTP Server, Tomcat, ActiveMQ, Struts, Kafka, Airflow, OFBiz, Solr and 300+ more) is published by security@apache.org and announced on the projects' mailing lists. VulniPulse ingests the CNA feed from NVD filtered to security@apache.org — official, machine-readable, with affected/fixed versions embedded in each description. Per-project security pages (httpd.apache.org/security, tomcat.apache.org/security-XX.html) carry the vendor detail.

Latest Apache advisories

Medium6.9Apache Updated

Medium [CVE-2026-66054] Allocation of Resources Without Limits or Throttling, Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++ bindings

Allocation of Resources Without Limits or Throttling, Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-66054
Unclassified
Oct 2, 2026
Medium6.9Apache Updated

Medium [CVE-2026-66331] Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Delphi bindings buffered transport

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Delphi bindings buffered transport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-66331
Unclassified
Oct 2, 2026
Medium6.3Apache Updated

Medium [CVE-2026-94652] Missing release of memory after effective lifetime vulnerability in Apache Thrift c++ bindings

Missing release of memory after effective lifetime vulnerability in Apache Thrift c++ bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94652
Unclassified
Oct 2, 2026
Medium6.3Apache Updated

Medium [CVE-2026-94638] Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings

Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-94638
Unclassified
Oct 2, 2026
Medium6.3Apache

Medium [CVE-2026-92834] Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift C++ WebSocket server

Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift C++ WebSocket server. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-92834
Unclassified
Oct 2, 2026
Medium6.3Apache

Medium [CVE-2026-86536] Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift all JS bindings

Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift all JS bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0 and re-generate JS code, which fixes the issue.

CVE-2026-86536
Unclassified
Oct 2, 2026
Medium6.9Apache

Medium [CVE-2026-85088] Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift

Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift. Both libraries install a default access manager for client sockets — TSSLSocketFactory does so in C++, and the accessManager property does so in D — which compares the peer certificate against the host name that was connected to. That comparison walks the subjectAltName dNSName entries first and consults the certificate Common Name afterwards. A name that does not match yields a "skip" result rather than a rejection, so a certificate whose subjectAltName entries are all present and all non-matching falls through to the Common Name, which can then satisfy the check. RFC 6125 section 6.4.4, and RFC 9525 section 2, require that the Common Name is not consulted when a dNSName subjectAltName is present. A certificate carrying subjectAltName entries for one name and a Common Name for another is therefore accepted for a connection to the second name. Exploitation requires an attacker positioned on the network path who holds a certificate that chains to a certificate authority in the client's trust store and whose Common Name matches the connected host Public certificate authorities have not issued on Common Name alone for many years, so this is principally a concern for deployments using a private or enterprise public-key infrastructure.

CVE-2026-85088
Unclassified
Oct 2, 2026
Medium6.9Apache

Medium [CVE-2026-85087] Improper certificate validation, Return of wrong status code vulnerability in Apache Thrift python bindings

Improper certificate validation, Return of wrong status code vulnerability in Apache Thrift python bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-85087
Unclassified
Oct 2, 2026
Medium6.9Apache

Medium [CVE-2026-85086] Improper certificate validation, Initialization of a resource with an insecure default vulnerability in Apache Thrift perl bindings

Improper certificate validation, Initialization of a resource with an insecure default vulnerability in Apache Thrift perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-85086
Unclassified
Oct 2, 2026
Medium6.3Apache

Medium [CVE-2026-85483] Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift c_glib bindings

Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

CVE-2026-85483
Unclassified
Oct 2, 2026
Medium5.3Apache

Medium [CVE-2026-79768] Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68

Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in ) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

CVE-2026-79768
HTTP Server
Oct 1, 2026
Medium5.3Apache

Medium [CVE-2026-58415] Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the.DAV state directory This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68

Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the.DAV state directory This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

CVE-2026-58415
HTTP Server
Oct 1, 2026
Medium4.3Apache

Medium [CVE-2026-42528] memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes

A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to version 2.4.69, which fixes this issue Affected product named by the advisory: Apache HTTP Server.

CVE-2026-42528
HTTP Server
Oct 1, 2026
Medium5.1Apache

Medium [CVE-2026-94276] Improper Authentication vulnerability in Apache APISIX

Improper Authentication vulnerability in Apache APISIX. On a route using openid-connect plugin with remote introspection against an authorization server that serves multiple issuers, a token that introspects as active for one issuer may get accepted on a route restricted to another. This issue affects Apache APISIX: from 3.12.0 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue.

CVE-2026-94276
Infra & Gateways
Oct 1, 2026
Medium6.3Apache

Medium [CVE-2026-94269] Use of Non-Canonical URL paths for authorization decisions vulnerability in Apache APISIX

Use of Non-Canonical URL paths for authorization decisions vulnerability in Apache APISIX. In some configurations where a permissive route overlaps a protected one, a crafted encoded path can reach an upstream endpoint that the matched route's policies were never meant to cover. A request that should have been rejected is served instead, giving unauthenticated access to a protected upstream endpoint. This issue affects Apache APISIX: from 2.14.1 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue.

CVE-2026-94269
Infra & Gateways
Oct 1, 2026
Medium6.4Apache

Medium [CVE-2026-94212] Improper verification of cryptographic signature vulnerability in Apache APISIX

Improper verification of cryptographic signature vulnerability in Apache APISIX. Any unauthenticated attacker could impersonate any user on every route protected by the saml-auth plugin under default configuration. This issue affects Apache APISIX: from 3.17.0 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue.

CVE-2026-94212
Infra & Gateways
Oct 1, 2026
Medium5.3Apache

Medium [CVE-2026-82806] Exposure of data element to wrong session vulnerability in Apache APISIX

Exposure of data element to wrong session vulnerability in Apache APISIX. This issue affects Apache APISIX: from 2.3.0 before 3.7.0. Under a supported authz-keycloak configuration, a request's authorization scope could persist into later requests on the same route, leading to unintended authorization expansion and inconsistent access-control decisions. Users are recommended to upgrade to version 3.7.0 or higher, which fixes the issue.

CVE-2026-82806
Infra & Gateways
Oct 1, 2026
Medium5.7Apache

Medium [CVE-2026-78242] Insertion of sensitive information into log file vulnerability in Apache APISIX

Insertion of sensitive information into log file vulnerability in Apache APISIX. This vulnerability can cause the unmasked header value to be written to the log sink under a certain response structure. This issue affects Apache APISIX: 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue.

CVE-2026-78242
Infra & Gateways
Oct 1, 2026
Medium4.8Apache

Medium [CVE-2026-92899] Apache CXF: Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused

Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes. The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the Nonce: the password digest still verified, but the token no longer matched the remembered one, so the replay was accepted. Since a UsernameToken does not cover the message body, the captured token could then be reused on requests of the attacker's choosing until it expired. Affects deployments with a nonce replay cache configured, as Apache CXF has by default, and only tokens using a password digest. The cache is now keyed on the decoded Nonce. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

CVE-2026-92899
Unclassified
Sep 30, 2026
Medium6.5Apache

Medium [CVE-2026-58624 +1] Improper input validation in sshd-git in Apache MINA SSHD, versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5

Improper input validation in sshd-git in Apache MINA SSHD, versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though class GitPgmCommandFactory a way to configure an Apache MINA SSHD server such that authenticated SSH clients can remotely execute git commands via the JGit library on git repositories stored on the server. In CVE-2026-58624 this mechanism was restricted to only a few git commands, including "git archive" without "--output" or "-o" options such that the resulting archive would not be written on the server but instead sent back to the client over the SSH connection. The fix done for CVE-2026-58624 was insufficient as it missed removing the single-argument "-o=file.zip" version of the command parameter from the "archive" command. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.

CVE-2026-58624CVE-2026-93995
Unclassified
Sep 30, 2026

← All vendors