oss-security·1d ago highCVE-2026-82384: Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint#apache#apache-roller#deserializationCVE-2026-82384 17 sources
oss-security·2d agoCVE-2026-92564: Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing#apache#qpid#broker-jCVE-2026-92564 6 sources
oss-security·2d agoCVE-2026-57590: Apache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unauthorized Cross-Project Operations#apache#dolphinscheduler#cve-2026-57590CVE-2026-57590
GBHackers·3d ago highApache Tomcat 11.0.26 Fixes 12 Security Flaws Enabling WebSocket Bypass and DoS Attacks#apache#tomcat#websocket 3 min
Cyber Security News·3d ago highApache Tomcat Update Fixes WebSocket and HTTP/2 Flaws Affecting Server Security#apache#tomcat#websocket 3 min
oss-security·3d ago highCVE-2026-76183: Apache Tomcat: Bypass of security constraints for WebSocket endpoints#apache#tomcat#websocketCVE-2026-76183 15 sources
oss-security·3d agoCVE-2026-91928: Apache Sling XSS: Sanitizer bypass, uncontrolled resource consumption and failure pf protection mechanisms#apache#sling#xssCVE-2026-91928 7 sources
oss-security·3d ago highCVE-2026-31377: Apache Doris: Improper Authentication Allows Unauthorized Access to FE Meta Service#apache-doris#cve-2026-31377#authenticationCVE-2026-31377 2 sources
oss-security·3d agoCVE-2026-82331: Apache BuildStream: tar source extraction escape#cve-2026-82331#apache#buildstreamCVE-2026-82331
SANS Internet Storm Center·4d agoThe Truth about GET and HTTP Standards, (Tue, Sep 22nd)#apache#http#nginxResearch
oss-security·8d agoCVE-2026-91863: Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows denial of service#apache#denial-of-service#javaCVE-2026-91863 5 sources
oss-security·10d ago highCVE-2026-76646: Apache MyFaces: Denial of Service via Unbounded Request Parsing#apache#cve-2026-76646#denial-of-serviceCVE-2026-76646 2 sources
oss-security·10d ago highCVE-2026-87976: Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles#apache#extension-bundles#javaCVE-2026-87976 5 sources1
oss-security·11d agoCVE-2026-59969: Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode#apache#certificate-validation#cveCVE-2026-59969
oss-security·11d ago highCVE-2026-59739: Apache ZooKeeper: Information disclosure via SetWatches reconnect replay#acl#apache#cveCVE-2026-59739
oss-security·12d agoCVE-2026-87802: Apache Syncope: SRA OAuth2 JWT signature verification bypass#apache#cve-2026-87802#jwtCVE-2026-878021
oss-security·12d agoCVE-2026-86460: Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence#apache#cve-2026-86460#cypher-injectionCVE-2026-864601
oss-security·12d agoCVE-2026-82232: Apache Syncope: SQL injection via sort parameter in Task search#apache#cve-2026-82232#jpaCVE-2026-82232
oss-security·12d agoCVE-2026-78336: Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user#apache#cve-2026-78336#oidcCVE-2026-783361
oss-security·12d agoCVE-2026-78330: Apache Syncope: Privilege escalation for admin user via JWT authentication#apache#cve-2026-78330#jwksCVE-2026-78330
oss-security·12d agoCVE-2026-78318: Apache Syncope: Unauthenticated reflected XSS in Console and Enduser#apache#console#cve-2026-78318CVE-2026-783181
oss-security·12d agoCVE-2026-77883: Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist#apache#cve-2026-77883#information-disclosureCVE-2026-778832
oss-security·12d agoCVE-2026-77181: Apache Syncope: ClientApp update entitlement not effective#access-control#apache#authorizationCVE-2026-77181
oss-security·12d agoCVE-2026-75015: Apache Syncope: Nested secrets leak cleartext into audit records readable#apache#audit-records#credential-leakCVE-2026-750151