Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1725

Browse all 1725 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE IDTitleCVSSSeverityPublished
CVE-2025-27522 Apache InLong: JDBC Vulnerability during verification processing — Apache InLongCWE-502 8.1AIHighAI2025-05-28
CVE-2025-35003 Apache NuttX RTOS: NuttX Bluetooth Stack HCI and UART DoS/RCE Vulnerabilities. — Apache NuttX RTOSCWE-119 8.8AIHighAI2025-05-26
CVE-2025-47436 Apache ORC: Potential Heap Buffer Overflow during C++ LZO Decompression — Apache ORCCWE-122 7.8AIHighAI2025-05-14
CVE-2025-26864 Apache IoTDB: Exposure of Sensitive Information in IoTDB OpenID Authentication — Apache IoTDBCWE-200 7.5AIHighAI2025-05-14
CVE-2025-26795 Apache IoTDB JDBC driver: Exposure of Sensitive Information in IoTDB JDBC driver — Apache IoTDB JDBC driverCWE-200 7.5AIHighAI2025-05-14
CVE-2024-24780 Apache IoTDB: Remote Code Execution with untrusted URI of User-defined function — Apache IoTDB 8.8AIHighAI2025-05-14
CVE-2025-27696 Apache Superset: Incorrect authorization leading to resource ownership takeover — Apache SupersetCWE-863 6.5AIMediumAI2025-05-13
CVE-2025-46392 Apache Commons Configuration: Uncontrolled Resource Consumption when loading untrusted configurations in 1.x — Apache Commons ConfigurationCWE-400 7.5AIHighAI2025-05-09
CVE-2025-27533 Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation — Apache ActiveMQCWE-789 7.5AIHighAI2025-05-07
CVE-2025-46762 Apache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadata — Apache Parquet JavaCWE-73 9.8AICriticalAI2025-05-06
CVE-2025-31651 Apache Tomcat: Bypass of rules in Rewrite Valve — Apache TomcatCWE-116 9.1AICriticalAI2025-04-28
CVE-2025-31650 Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame — Apache TomcatCWE-459 7.5AIHighAI2025-04-28
CVE-2025-27820 Apache HttpComponents: PSL (Public Suffix List) validation bypass — Apache HttpComponents--2025-04-24
CVE-2025-26413 Apache Kvrocks: The server was crashed by the negative offset — Apache KvrocksCWE-20 7.5 -2025-04-22
CVE-2025-29953 Apache ActiveMQ NMS OpenWire Client: deserialization allowlist bypass — Apache ActiveMQ NMS OpenWire ClientCWE-502 9.8 -2025-04-18
CVE-2024-56736 Apache HertzBeat: Server-Side Request Forgery (SSRF) in Api Config Oss — Apache HertzBeatCWE-918 9.1AICriticalAI2025-04-16
CVE-2025-24859 Apache Roller: Insufficient Session Expiration on Password Change — Apache RollerCWE-613 8.8AIHighAI2025-04-14
CVE-2025-27391 Apache ActiveMQ Artemis: Passwords leaking from broker properties in the debug log — Apache ActiveMQ ArtemisCWE-532 7.5 -2025-04-09
CVE-2025-31672 Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names — Apache POICWE-20 7.5 -2025-04-09
CVE-2025-30677 Apache Pulsar IO Kafka Connector, Apache Pulsar IO Kafka Connect Adaptor: Sensitive information logged in Pulsar's Apache Kafka Connectors — Apache Pulsar IO Kafka ConnectorCWE-532 8.1AIHighAI2025-04-09
CVE-2025-30473 Apache Airflow Common SQL Provider: Remote Code Execution via Sql Injection — Apache Airflow Common SQL ProviderCWE-89 8.8AIHighAI2025-04-07
CVE-2024-53868 Apache Traffic Server: Malformed chunked message body allows request smuggling — Apache Traffic ServerCWE-444 7.5AIHighAI2025-04-03
CVE-2025-30676 Apache OFBiz: Stored XSS Vulnerability — Apache OFBizCWE-80 6.1 -2025-04-01
CVE-2025-30177 Apache Camel: Camel-Undertow Message Header Injection via Improper Filtering — Apache Camel 7.5 -2025-04-01
CVE-2024-56325 Apache Pinot: Authentication bypass issue. If the path does not contain / and contain . authentication is not required — Apache PinotCWE-288 9.8AICriticalAI2025-04-01
CVE-2025-29868 Apache Answer: Using externally referenced images can leak user privacy. — Apache AnswerCWE-495 6.5 -2025-04-01
CVE-2025-30065 Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata — Apache Parquet JavaCWE-502 9.8AICriticalAI2025-04-01
CVE-2025-27427 Apache ActiveMQ Artemis: Address routing-type can be updated by user without the createAddress permission — Apache ActiveMQ ArtemisCWE-863 6.5 -2025-04-01
CVE-2025-30067 Apache Kylin: The remote code execution via jdbc url — Apache KylinCWE-94 9.8AICriticalAI2025-03-27
CVE-2024-48944 Apache Kylin: SSRF vulnerability in the diagnosis api — Apache KylinCWE-918 4.4AIMediumAI2025-03-27

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.