Known Vulnerabilities for products from Apache

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Apache".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-68981 json Not Provided 2026-08-03 2026-08-04
CVE-2026-68980 json Not Provided 2026-08-03 2026-08-04
CVE-2026-68979 json Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization chec... Not Provided 2026-08-03 2026-08-05
CVE-2026-68481 json In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionS... Not Provided 2026-08-06 2026-08-07
CVE-2026-68080 json It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker ... Not Provided 2026-08-05 2026-08-06
CVE-2026-68079 json Not Provided 2026-08-06 2026-08-07
CVE-2026-68078 json It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker... Not Provided 2026-08-05 2026-08-06
CVE-2026-68077 json An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive... Not Provided 2026-08-05 2026-08-06
CVE-2026-68075 json An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. Th... Not Provided 2026-08-05 2026-08-06
CVE-2026-68074 json Not Provided 2026-08-05 2026-08-06
CVE-2026-68073 json A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of serv... Not Provided 2026-08-05 2026-08-06
CVE-2026-66909 json Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no... Not Provided 2026-08-06 2026-08-07
CVE-2026-66713 json Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache... Not Provided 2026-07-28 2026-08-05
CVE-2026-66391 json Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache ... Not Provided 2026-07-27 2026-08-05
CVE-2026-66390 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This is... Not Provided 2026-07-27 2026-08-05
CVE-2026-66299 json Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat:... Not Provided 2026-07-28 2026-08-05
CVE-2026-66144 json Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API i... Not Provided 2026-07-24 2026-07-27
CVE-2026-66143 json It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via... Not Provided 2026-07-24 2026-07-27
CVE-2026-66142 json Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested struct... Not Provided 2026-07-24 2026-07-27
CVE-2026-66053 json Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apa... Not Provided 2026-07-27 2026-07-27

Known software with vulnerabilities from Apache

Type Vendor Product Version
ApplicationApacheAccumulo1.10.0
ApplicationApacheActivemq-
ApplicationApacheActivemq Apollo1.0
ApplicationApacheActivemq Artemis-
ApplicationApacheAirflow0.1
ApplicationApacheAllura1.0.0
ApplicationApacheAmbari0.9
ApplicationApacheAmqp 0-x Jms Client6.0.3
ApplicationApacheAmqp Jms Client0.9.0
ApplicationApacheAnt1.1
ApplicationApacheApache-ssl1.37
ApplicationApacheApache Test-
ApplicationApacheApisix1.2
ApplicationApacheApr-util0.9.1
ApplicationApacheArchiva0.9
ApplicationApacheArrow0.1.0
ApplicationApacheAsterixdb-
ApplicationApacheAtlas0.5.0
ApplicationApacheAxis-
ApplicationApacheAxis2-

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report