Known Vulnerabilities for products from Apache
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Apache".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-68981 json | Not Provided | 2026-08-03 | 2026-08-04 | |
| CVE-2026-68980 json | Not Provided | 2026-08-03 | 2026-08-04 | |
| CVE-2026-68979 json | Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization chec... | Not Provided | 2026-08-03 | 2026-08-05 |
| CVE-2026-68481 json | In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionS... | Not Provided | 2026-08-06 | 2026-08-07 |
| CVE-2026-68080 json | It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker ... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-68079 json | Not Provided | 2026-08-06 | 2026-08-07 | |
| CVE-2026-68078 json | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-68077 json | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-68075 json | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. Th... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-68074 json | Not Provided | 2026-08-05 | 2026-08-06 | |
| CVE-2026-68073 json | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of serv... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-66909 json | Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no... | Not Provided | 2026-08-06 | 2026-08-07 |
| CVE-2026-66713 json | Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache... | Not Provided | 2026-07-28 | 2026-08-05 |
| CVE-2026-66391 json | Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache ... | Not Provided | 2026-07-27 | 2026-08-05 |
| CVE-2026-66390 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This is... | Not Provided | 2026-07-27 | 2026-08-05 |
| CVE-2026-66299 json | Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat:... | Not Provided | 2026-07-28 | 2026-08-05 |
| CVE-2026-66144 json | Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API i... | Not Provided | 2026-07-24 | 2026-07-27 |
| CVE-2026-66143 json | It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via... | Not Provided | 2026-07-24 | 2026-07-27 |
| CVE-2026-66142 json | Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested struct... | Not Provided | 2026-07-24 | 2026-07-27 |
| CVE-2026-66053 json | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apa... | Not Provided | 2026-07-27 | 2026-07-27 |
Known software with vulnerabilities from Apache
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Apache | Accumulo | 1.10.0 |
| Application | Apache | Activemq | - |
| Application | Apache | Activemq Apollo | 1.0 |
| Application | Apache | Activemq Artemis | - |
| Application | Apache | Airflow | 0.1 |
| Application | Apache | Allura | 1.0.0 |
| Application | Apache | Ambari | 0.9 |
| Application | Apache | Amqp 0-x Jms Client | 6.0.3 |
| Application | Apache | Amqp Jms Client | 0.9.0 |
| Application | Apache | Ant | 1.1 |
| Application | Apache | Apache-ssl | 1.37 |
| Application | Apache | Apache Test | - |
| Application | Apache | Apisix | 1.2 |
| Application | Apache | Apr-util | 0.9.1 |
| Application | Apache | Archiva | 0.9 |
| Application | Apache | Arrow | 0.1.0 |
| Application | Apache | Asterixdb | - |
| Application | Apache | Atlas | 0.5.0 |
| Application | Apache | Axis | - |
| Application | Apache | Axis2 | - |