Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1725

Browse all 1725 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

Found 106 results / 1725Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-38743 Apache Airflow: Dags endpoint might provide access to otherwise inaccessible entities — Apache AirflowCWE-1220 4.3AIMediumAI2026-04-24
CVE-2026-40690 Apache Airflow: Assets graph view bypasses DAG level access control displaying unrelated topologies and all DAGs names to unauthorized users — Apache AirflowCWE-1220 4.3AIMediumAI2026-04-24
CVE-2026-32690 Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1 — Apache AirflowCWE-668 7.5AIHighAI2026-04-18
CVE-2026-30898 Apache Airflow: Bad example of BashOperator shell injection via dag_run.conf — Apache AirflowCWE-77 8.8AIHighAI2026-04-18
CVE-2026-30912 Apache Airflow: Exposing stack trace in case of constraint error — Apache AirflowCWE-668 7.5AIHighAI2026-04-18
CVE-2026-25917 Apache Airflow: API extra-links triggers XCom deserialization/class instantiation (Airflow 3.1.5) — Apache AirflowCWE-502 9.8AICriticalAI2026-04-18
CVE-2026-32228 Apache Airflow: Users with asset materialization permisssions could trigger Dags they had no access to — Apache AirflowCWE-863 7.1AIHighAI2026-04-18
CVE-2026-31987 Apache Airflow: JWT token appearing in logs — Apache AirflowCWE-532 6.5AIMediumAI2026-04-16
CVE-2026-25219 Apache Airflow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access — Apache AirflowCWE-200 6.5 -2026-04-15
CVE-2025-54550 Apache Airflow: RCE by race condition in example_xcom dag — Apache AirflowCWE-94 8.8 -2026-04-15
CVE-2026-33858 Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API — Apache AirflowCWE-502 9.8 -2026-04-13
CVE-2025-66236 Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI — Apache AirflowCWE-532 9.6 -2026-04-13
CVE-2025-57735 Apache Airflow: Airflow Logout Not Invalidating JWT — Apache AirflowCWE-613 9.1AICriticalAI2026-04-09
CVE-2026-34538 Apache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure) — Apache AirflowCWE-668 6.5AIMediumAI2026-04-09
CVE-2026-28563 Apache Airflow: DAG authorization bypass — Apache AirflowCWE-732 4.3 -2026-03-17
CVE-2026-26929 Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata — Apache AirflowCWE-732 5.3AIMediumAI2026-03-17
CVE-2026-30911 Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization — Apache AirflowCWE-862 8.1AIHighAI2026-03-17
CVE-2026-28779 Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications — Apache AirflowCWE-668 9.8AICriticalAI2026-03-17
CVE-2025-27555 Apache Airflow: Connection Secrets not masked in UI when Connection are added via Airflow cli — Apache AirflowCWE-532 6.5AIMediumAI2026-02-24
CVE-2024-56373 Apache Airflow: SSTI to Code Execution in Airflow through Shared DB Information — Apache AirflowCWE-94 8.0AIHighAI2026-02-24
CVE-2025-65995 Apache Airflow: Disclosure of secrets to UI via kwargs — Apache AirflowCWE-209 6.5AIMediumAI2026-02-21
CVE-2026-22922 Apache Airflow: Airflow externalLogUrl Permission Bypass — Apache AirflowCWE-648 4.3AIMediumAI2026-02-09
CVE-2026-24098 Apache Airflow: Assigning single DAG permission leaked all DAGs Import Errors — Apache AirflowCWE-200 4.3AIMediumAI2026-02-09
CVE-2025-68675 Apache Airflow: proxy credentials for various providers might leak in task logs — Apache AirflowCWE-532 7.5 -2026-01-16
CVE-2025-68438 Apache Airflow: Secrets in rendered templates could contain parts of sensitive values when truncated — Apache AirflowCWE-200 7.5 -2026-01-16
CVE-2025-66388 Apache Airflow: Secrets in rendered templates not redacted properly and exposed in the UI — Apache AirflowCWE-201 6.5 -2025-12-15
CVE-2025-54941 Apache Airflow: Command injection in "example_dag_decorator" — Apache AirflowCWE-78 8.8AIHighAI2025-10-30
CVE-2025-62402 Apache Airflow: Airflow 3 API: /api/v2/dagReports executes DAG Python in API — Apache AirflowCWE-250 8.0AIHighAI2025-10-30
CVE-2025-62503 Apache Airflow: Privilege boundary bypass in bulk APIs (create action can upsert existing Pools/Connections/Variables) — Apache AirflowCWE-250 6.5AIMediumAI2025-10-30
CVE-2025-54831 Apache Airflow: Connection sensitive details exposed to users with READ permissions — Apache AirflowCWE-213 6.5 -2025-09-26

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.