apache
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting apache.
- CVE-2026-70469Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests7.5
- CVE-2026-81866Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration4.3
- CVE-2026-82561Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods6.5
- CVE-2026-86089Apache NiFi: Missing Process Group Authorization for Connector Migration7.1
- CVE-2026-87976Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles8.1
- CVE-2026-84501Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationProvider5.3
- CVE-2026-84439Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources5.3
- CVE-2026-79993Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znode7.5
- CVE-2026-59969Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode7.5
- CVE-2026-59739Apache ZooKeeper: Information disclosure via SetWatches reconnect replay7.5
- CVE-2026-86466Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validated8.1
- CVE-2026-76187Apache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session JWT9.8
- CVE-2026-76186Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity9.1
- CVE-2026-82310Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access7.2
- CVE-2026-86792Apache Airflow Apache Kafka provider: Connection-editor remote code execution on the Scheduler via Kafka connection callback configuration8.8