Known Vulnerabilities for products from Apache
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Apache".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-105244 json | Not Provided | 2026-10-06 | 2026-10-07 | |
| CVE-2026-105243 json | Not Provided | 2026-10-06 | 2026-10-07 | |
| CVE-2026-105242 json | Not Provided | 2026-10-06 | 2026-10-07 | |
| CVE-2026-105241 json | Not Provided | 2026-10-06 | 2026-10-07 | |
| CVE-2026-105240 json | Not Provided | 2026-10-06 | 2026-10-07 | |
| CVE-2026-105239 json | Not Provided | 2026-10-06 | 2026-10-07 | |
| CVE-2026-105111 json | Not Provided | 2026-10-06 | 2026-10-07 | |
| CVE-2026-104714 json | Not Provided | 2026-10-05 | 2026-10-06 | |
| CVE-2026-104713 json | Not Provided | 2026-10-05 | 2026-10-06 | |
| CVE-2026-104712 json | Not Provided | 2026-10-05 | 2026-10-06 | |
| CVE-2026-102497 json | The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or... | Not Provided | 2026-09-29 | 2026-10-06 |
| CVE-2026-102496 json | Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious sch... | Not Provided | 2026-09-29 | 2026-10-06 |
| CVE-2026-102495 json | Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing r... | Not Provided | 2026-09-29 | 2026-10-06 |
| CVE-2026-95616 json | An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can... | Not Provided | 2026-09-30 | 2026-10-06 |
| CVE-2026-94251 json | A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource ... | Not Provided | 2026-09-23 | 2026-10-06 |
| CVE-2026-94243 json | A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects... | Not Provided | 2026-09-23 | 2026-10-06 |
| CVE-2026-93546 json | Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access t... | Not Provided | 2026-10-01 | 2026-10-05 |
| CVE-2026-92899 json | Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce ... | Not Provided | 2026-09-30 | 2026-10-02 |
| CVE-2026-92609 json | Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated m... | Not Provided | 2026-09-25 | 2026-10-05 |
| CVE-2026-92608 json | Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message pr... | Not Provided | 2026-09-25 | 2026-10-05 |
Known software with vulnerabilities from Apache
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Apache | Accumulo | 1.10.0 |
| Application | Apache | Activemq | - |
| Application | Apache | Activemq Apollo | 1.0 |
| Application | Apache | Activemq Artemis | - |
| Application | Apache | Airflow | 0.1 |
| Application | Apache | Allura | 1.0.0 |
| Application | Apache | Ambari | 0.9 |
| Application | Apache | Amqp 0-x Jms Client | 6.0.3 |
| Application | Apache | Amqp Jms Client | 0.9.0 |
| Application | Apache | Ant | 1.1 |
| Application | Apache | Apache-ssl | 1.37 |
| Application | Apache | Apache Test | - |
| Application | Apache | Apisix | 1.2 |
| Application | Apache | Apr-util | 0.9.1 |
| Application | Apache | Archiva | 0.9 |
| Application | Apache | Arrow | 0.1.0 |
| Application | Apache | Asterixdb | - |
| Application | Apache | Atlas | 0.5.0 |
| Application | Apache | Axis | - |
| Application | Apache | Axis2 | - |