Vulnerabilities
397 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-60053 | Insufficient Session Expiration vulnerability in Apache Answer. Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained usable after the owning administrator was demoted or the account was marked inactive, suspended, or deleted, allowing continued access until the keys were explicitly removed. Users are recommended to upgrade to version 2.0.2, which fixes the issue. NVD description · AI analysis pending | 9.1 group max | <1% |
| — | ||
| CVE-2026-61486 | ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. Lucy is now maintained outside of the ASF at https://github.com/lucysearch . This issue has been fixed in 0.8.0 there. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2026-68074 | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2026-67590 | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2026-67551 | pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2026-66274 | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2026-68981 | Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which relocates response compression to Jetty Server and disables decompression of gzip-encoded HTTP requests. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2026-61372 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena Fuseki: through 6.1.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2026-64607 | HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or uns HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2026-62391 | The security fix for CVE-2025-66518 is incomplete. The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. This issue affects Apache Kyuubi: from 1.6.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which fixes the issue. NVD description · AI analysis pending | 8.1 | <1% |
| — | ||
| CVE-2026-44615 | Path traversal vulnerability in Apache Zeppelin. Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a note, or access to folder operations, could supply traversal segments in note or folder paths. Zeppelin composed these values into filesystem paths using the server's filesystem or Hadoop identity without ensuring that the result remained under the configured notebook directory. This could allow notebook files or directories to be moved, written, or deleted outside the notebook root. This issue affects Apache Zeppelin versions 0.9.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2026-66756 +1 in the same advisory: …66755 | Improper Protection of Alternate Path vulnerability in Apache Tika. Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue. NVD description · AI analysis pending | 6.9 group max | <1% |
| — | ||
| CVE-2026-52680 | Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequences in the filename and cause the Kyuubi server process to write controlled content outside the intended upload directory, subject to filesystem permissions. This issue affects Apache Kyuubi: from 1.7.0 through 1.11.1. Users are recommended to upgrade to version 1.12.0, which fixes the issue. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2026-28813 | Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.4, which fixes this issue. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2026-44617 | LDAP filter injection vulnerability in Apache Zeppelin. LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters instead of RFC 4515 filter escaping, leaving special filter characters insufficiently escaped. This is an incomplete fix of CVE-2024-31867. This issue affects Apache Zeppelin versions 0.11.1, 0.11.2, and 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue. NVD description · AI analysis pending | 6.5 group max | <1% |
| — |