apache
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting apache.
- CVE-2026-71559Apache Fory: Uncaught panic (remote DoS) in Go meta-string decoder from untrusted metadata7.5
- CVE-2026-71558Apache Fory: Heap type confusion in C++ polymorphic smart-pointer deserialization9.8
- CVE-2026-71560Apache Fory: Out-of-bounds heap read in C++ struct deserializer tagged-int fast-path9.1
- CVE-2025-49506Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack7.5
- CVE-2026-32327Apache Portable Runtime Utility: apr-util XML stack recursion crash9.1
- CVE-2026-34191Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle9.1
- CVE-2026-34501Apache Portable Runtime Utility: Heap buffer overflow in APR redis client7.5
- CVE-2026-34502Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client7.5
- CVE-2026-57818Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider8.1
- CVE-2026-61466Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation9.1
- CVE-2026-63687Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters9.1
- CVE-2026-65583Apache CXF: Self-issued ID token claims validation skipped9.1
- CVE-2026-68079Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay9.8
- CVE-2026-68481Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider7.5
- CVE-2026-65432Apache CXF: XXE via WSDL/XSD import parsing7.5