Known Vulnerabilities for Apache by Chorny
Listed below are 10 of the newest known vulnerabilities associated with "Apache" by "Chorny".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-43975 json | FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName be... | Not Provided | 2026-05-06 | 2026-05-06 |
| CVE-2026-43870 json | Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralizat... | Not Provided | 2026-05-05 | 2026-05-06 |
| CVE-2026-43869 json | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: befo... | Not Provided | 2026-05-05 | 2026-05-06 |
| CVE-2026-43868 json | Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0.... | Not Provided | 2026-05-05 | 2026-05-05 |
| CVE-2026-43646 json | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket. This issue affects Apache Wicket:... | Not Provided | 2026-05-06 | 2026-05-06 |
| CVE-2026-42812 json | In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and w... | Not Provided | 2026-05-04 | 2026-05-04 |
| CVE-2026-42811 json | In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a c... | Not Provided | 2026-05-04 | 2026-05-04 |
| CVE-2026-42810 json | Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies... | Not Provided | 2026-05-04 | 2026-05-04 |
| CVE-2026-42809 json | Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective tab... | Not Provided | 2026-05-04 | 2026-05-04 |
| CVE-2026-42779 json | The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: ... | Not Provided | 2026-05-01 | 2026-05-01 |