Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1725

Browse all 1725 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE IDTitleCVSSSeverityPublished
CVE-2021-33193 Request splitting via HTTP/2 method injection and mod_proxy — Apache HTTP Server 7.5 -2021-08-16
CVE-2021-21501 ServiceComb ServiceCenter Directory Traversal — Apache ServiceCombCWE-22 9.1 -2021-08-10
CVE-2021-37578 Remote code execution via RMI — Apache jUDDICWE-502 9.8 -2021-07-29
CVE-2021-33900 StartTLS and SASL confidentiality protection bypass — Apache Directory StudioCWE-311 7.5 -2021-07-26
CVE-2021-28131 Impala logs contain secrets — Apache ImpalaCWE-288 8.8 -2021-07-22
CVE-2021-36374 Apache Ant ZIP, and ZIP based, archive denial of service vulerability — Apache AntCWE-130 5.5 -2021-07-14
CVE-2021-36373 Apache Ant TAR archive denial of service vulnerability — Apache AntCWE-130 5.5 -2021-07-14
CVE-2021-36090 Apache Commons Compress 1.0 to 1.20 denial of service vulnerability — Apache Commons CompressCWE-130 7.5 -2021-07-13
CVE-2021-35517 Apache Commons Compress 1.1 to 1.20 denial of service vulnerability — Apache Commons CompressCWE-130 7.5 -2021-07-13
CVE-2021-35516 Apache Commons Compress 1.6 to 1.20 denial of service vulnerability — Apache Commons CompressCWE-130 7.5 -2021-07-13
CVE-2021-35515 Apache Commons Compress 1.6 to 1.20 denial of service vulnerability — Apache Commons CompressCWE-834 7.5 -2021-07-13
CVE-2021-33037 Incorrect Transfer-Encoding handling with HTTP/1.0 — Apache TomcatCWE-444 5.3 -2021-07-12
CVE-2021-30640 Auth weakness in JNDIRealm — Apache Tomcat 6.5 -2021-07-12
CVE-2021-30639 DoS after non-blocking IO error — Apache Tomcat 6.5 -2021-07-12
CVE-2021-30129 DoS/OOM leak vulnerability in Apache Mina SSHD Server — Apache Mina SSHD 9.1 -2021-07-12
CVE-2021-33192 Display information UI XSS — Apache Jena FusekiCWE-79 6.1 -2021-07-05
CVE-2021-26920 Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended — Apache Druid 6.5 -2021-07-02
CVE-2021-35474 Dynamic stack buffer overflow in cachekey plugin — Apache Traffic ServerCWE-121 9.8 -2021-06-30
CVE-2021-32567 Reading HTTP/2 frames too many times — Apache Traffic ServerCWE-20 7.5 -2021-06-30
CVE-2021-32566 Specific sequence of HTTP/2 frames can cause ATS to crash — Apache Traffic ServerCWE-20 7.5 -2021-06-30
CVE-2021-32565 HTTP Request Smuggling, content length with invalid charters — Apache Traffic ServerCWE-444 7.5 -2021-06-29
CVE-2021-27577 Incorrect handling of url fragment leads to cache poisoning — Apache Traffic ServerCWE-444 7.5 -2021-06-29
CVE-2021-26461 malloc, realloc and memalign implementations are vulnerable to integer wrap-arounds — Apache NuttXCWE-190 9.8 -2021-06-21
CVE-2021-30468 Apache CXF Denial of service vulnerability in parsing JSON via JsonMapObjectReaderWriter — Apache CXFCWE-400 7.5 -2021-06-16
CVE-2020-9493 Java deserialization in Chainsaw — Apache ChainsawCWE-502 9.8 -2021-06-16
CVE-2021-31618 NULL pointer dereference on specially crafted HTTP/2 request — Apache HTTP ServerCWE-476 7.5 -2021-06-15
CVE-2021-31811 A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading a tiny file — Apache PDFBoxCWE-789 5.5 -2021-06-12
CVE-2021-31812 A carefully crafted PDF file can trigger an infinite loop while loading the file — Apache PDFBoxCWE-834 5.5 -2021-06-12
CVE-2021-30641 Unexpected URL matching with 'MergeSlashes OFF' — Apache HTTP Server 5.3 -2021-06-10
CVE-2021-26691 Apache HTTP Server mod_session response handling heap overflow — Apache HTTP ServerCWE-122 9.8 -2021-06-10

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.