apache-software-foundation
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting apache-software-foundation.
- CVE-2026-73633Apache Struts: Unbounded read of a JSON request body7.5
- CVE-2026-66256Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API)7.2
- CVE-2026-73237Apache Allura: XSS in markdown pipeline6.1
- CVE-2026-73238Apache Allura: XSS in code display6.1
- CVE-2026-73239Apache Allura: Missing permission checks IDOR6.5
- CVE-2026-73240Apache Allura: Git command injection9.8
- CVE-2026-59242Apache Airflow: Arbitrary airflow.* class instantiation on the API server via the XCom deserialize endpoint5.4
- CVE-2026-54183Apache Airflow: Airflow Variables were not masked in the UI for authenticated users4.3
- CVE-2026-67260Apache Airflow: DAG-author remote code execution on the Scheduler via awaiting_input next_kwargs deserialization7.3
- CVE-2026-67587Apache Airflow: DAG-author remote code execution on the Scheduler via a Serde `Callback` deserialization gadget8.8
- CVE-2026-65017Apache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi-team masking bypass)6.5
- CVE-2026-68968Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretations of the backfill id7.5
- CVE-2026-68969Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartext6.5
- CVE-2026-68970Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UI6.5
- CVE-2026-68971Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run result endpoints6.5