apache-software-foundation
Latest CVEs
The 15 most recently published vulnerabilities affecting apache-software-foundation.
- CVE-2026-44615Path traversal in NotebookRepo note and folder path composition6.5
- CVE-2026-64607Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS5.3
- CVE-2026-62391Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases8.1
- CVE-2026-52680Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write9.8
- CVE-2026-48910Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing6.5
- CVE-2026-28814Apache JSPWiki: Pre-Authentication Arbitrary Wiki Markup Rendering7.5
- CVE-2026-28813Apache JSPWiki: JSPWiki vulnerable to JSON hijacking8.8
- CVE-2026-28812Apache JSPWiki: UserManager does not sanity-check user database at startup9.8
- CVE-2026-28811Apache JSPWiki: Error Handling - Reveals Error Details7.5
- CVE-2026-44617Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-318676.5
- CVE-2026-44616Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction6.5
- CVE-2026-44613Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling6.1
- CVE-2026-50622Apache Atlas: Missing Authorization on Admin Endpoints8.8
- CVE-2026-23904Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy7.3
- CVE-2026-65100Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header encode4.8