apache-software-foundation
Latest CVEs
The 15 most recently published vulnerabilities affecting apache-software-foundation.
- CVE-2026-75157Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDIT (asset-triggered scheduling suppression)
- CVE-2026-92230Apache Karaf: Improper release of ClassLoader references via static ThreadLocal caching7.5
- CVE-2026-70469Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests7.5
- CVE-2026-81866Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration
- CVE-2026-82561Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods6.5
- CVE-2026-86089Apache NiFi: Missing Process Group Authorization for Connector Migration
- CVE-2026-87976Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles
- CVE-2026-76646Apache MyFaces: Denial of Service via Unbounded Request Parsing7.5
- CVE-2026-68536Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability9.8
- CVE-2026-84501Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationProvider5.3
- CVE-2026-84439Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources5.3
- CVE-2026-79993Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znode7.5
- CVE-2026-59969Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode7.5
- CVE-2026-59739Apache ZooKeeper: Information disclosure via SetWatches reconnect replay7.5
- CVE-2026-86466Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validated8.1