Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 1771

Browse all 1771 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE IDTitleCVSSSeverityPublished
CVE-2025-29953 Apache ActiveMQ NMS OpenWire Client: deserialization allowlist bypass — Apache ActiveMQ NMS OpenWire ClientCWE-502 9.8 -2025-04-18
CVE-2024-56736 Apache HertzBeat: Server-Side Request Forgery (SSRF) in Api Config Oss — Apache HertzBeatCWE-918 9.1AICriticalAI2025-04-16
CVE-2025-24859 Apache Roller: Insufficient Session Expiration on Password Change — Apache RollerCWE-613 8.8AIHighAI2025-04-14
CVE-2025-27391 Apache ActiveMQ Artemis: Passwords leaking from broker properties in the debug log — Apache ActiveMQ ArtemisCWE-532 7.5 -2025-04-09
CVE-2025-31672 Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names — Apache POICWE-20 7.5 -2025-04-09
CVE-2025-30677 Apache Pulsar IO Kafka Connector, Apache Pulsar IO Kafka Connect Adaptor: Sensitive information logged in Pulsar's Apache Kafka Connectors — Apache Pulsar IO Kafka ConnectorCWE-532 8.1AIHighAI2025-04-09
CVE-2025-30473 Apache Airflow Common SQL Provider: Remote Code Execution via Sql Injection — Apache Airflow Common SQL ProviderCWE-89 8.8AIHighAI2025-04-07
CVE-2024-53868 Apache Traffic Server: Malformed chunked message body allows request smuggling — Apache Traffic ServerCWE-444 7.5AIHighAI2025-04-03
CVE-2025-30676 Apache OFBiz: Stored XSS Vulnerability — Apache OFBizCWE-80 6.1 -2025-04-01
CVE-2025-30177 Apache Camel: Camel-Undertow Message Header Injection via Improper Filtering — Apache Camel 7.5 -2025-04-01
CVE-2024-56325 Apache Pinot: Authentication bypass issue. If the path does not contain / and contain . authentication is not required — Apache PinotCWE-288 9.8AICriticalAI2025-04-01
CVE-2025-29868 Apache Answer: Using externally referenced images can leak user privacy. — Apache AnswerCWE-495 6.5 -2025-04-01
CVE-2025-30065 Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata — Apache Parquet JavaCWE-502 9.8AICriticalAI2025-04-01
CVE-2025-27427 Apache ActiveMQ Artemis: Address routing-type can be updated by user without the createAddress permission — Apache ActiveMQ ArtemisCWE-863 6.5 -2025-04-01
CVE-2025-30067 Apache Kylin: The remote code execution via jdbc url — Apache KylinCWE-94 9.8AICriticalAI2025-03-27
CVE-2024-48944 Apache Kylin: SSRF vulnerability in the diagnosis api — Apache KylinCWE-918 4.4AIMediumAI2025-03-27
CVE-2024-53679 Apache VCL: XSS vulnerability in User Lookup impacting user privileges — Apache VCLCWE-79 5.4AIMediumAI2025-03-25
CVE-2024-53678 Apache VCL: SQL injection vulnerability in New Block Allocation form — Apache VCLCWE-89 5.3AIMediumAI2025-03-25
CVE-2025-27553 Apache Commons VFS: Possible path traversal issue when using NameScope.DESCENDENT — Apache Commons VFSCWE-23--2025-03-23
CVE-2025-30474 Apache Commons VFS: Failing to find an FTP file can reveal the URI's password in an error message — Apache Commons VFSCWE-200 7.5 -2025-03-23
CVE-2025-26796 Apache Oozie: XSS in Oozie Web Console — Apache OozieCWE-79 6.1 -2025-03-22
CVE-2025-27888 Apache Druid: Server-Side Request Forgery and Cross-Site Scripting — Apache DruidCWE-918 5.4 -2025-03-20
CVE-2024-54016 compression bomb attack in Apache Seata Server — Apache Seata (incubating)CWE-409 9.1 -2025-03-20
CVE-2024-47552 Apache Seata (incubating): Deserialization of untrusted Data in jraft mode in Apache Seata Server — Apache Seata (incubating)CWE-502 9.8 -2025-03-20
CVE-2025-27018 Apache Airflow MySQL Provider: SQL injection in MySQL provider core function — Apache Airflow MySQL ProviderCWE-89 8.8 -2025-03-19
CVE-2025-27017 Apache NiFi: Potential Insertion of MongoDB Password in Provenance Record — Apache NiFiCWE-538 6.5 -2025-03-12
CVE-2025-27867 Apache Felix HTTP Webconsole Plugin: XSS in HTTP Webconsole Plugin — Apache Felix HTTP Webconsole PluginCWE-79 6.1 -2025-03-12
CVE-2025-29891 Apache Camel: Camel Message Header Injection through request parameters — Apache CamelCWE-164 8.2 -2025-03-12
CVE-2025-24813 Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT — Apache TomcatCWE-44 8.8 -2025-03-10
CVE-2025-26865 Apache OFBiz: Server-Side Template Injection affecting the ecommerce plugin leading to possible RCE — Apache OFBizCWE-1336 9.8 -2025-03-10

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.