Vulnerability index

Browse CVEs

80 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Struts HIGH 7.5
CVE-2026-73634

Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violatio…

Fix unknown
Fix from $4,900 2026-08-15
Struts HIGH 7.5
CVE-2026-73633

Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSO…

No fix yet
Fix from $4,900 2026-08-14
Cxf HIGH 7.5
CVE-2026-57819

Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, …

Fix: 3.6.12 / 4.1.8+
Fix from $1,950 2026-08-06
Cxf HIGH 7.5
CVE-2026-64958

An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with ma…

Fix: 3.6.12 / 4.1.8+
Fix from $1,950 2026-08-06
Answer HIGH 7.5
CVE-2026-48834

Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticate…

Fix: 2.0.2+
Fix from $1,950 2026-08-05
Traffic Server HIGH 8.6
CVE-2026-58182

The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Serv…

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Traffic Server HIGH 7.5
CVE-2026-65324

Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This …

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Traffic Server HIGH 7.5
CVE-2026-58151

Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic …

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Tomcat HIGH 7.5
CVE-2026-66299

Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through…

Fix: 9.0.121 / 10.1.58+
Fix from $1,950 2026-07-28
Neethi HIGH 7.5
CVE-2026-66142

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to …

Fix: 3.2.3+
Fix from $1,950 2026-07-24
Neethi HIGH 7.5
CVE-2026-66143

It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies…

No fix yet
Fix from $1,950 2026-07-24
Neethi HIGH 7.5
CVE-2026-66144

Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of …

Fix: 3.2.3+
Fix from $1,950 2026-07-24
Traffic Server HIGH 7.5
CVE-2026-59173

Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from …

Fix: 9.2.14 / 10.1.3+
Fix from $1,950 2026-07-18
Iotdb HIGH 7.5
CVE-2026-24012

Uncontrolled Resource Consumption vulnerability in Apache IoTDB.  Some interface fails to impose reasonable limits on the time span and aggregation …

Fix: 2.0.8+
Fix from $1,950 2026-07-06
Httpcomponents Core HIGH 7.5
CVE-2026-54428

Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earl…

Fix: after 5.4.2
Fix from $1,950 2026-07-01
Httpcomponents Core HIGH 7.5
CVE-2026-54399

Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlie…

Fix: after 5.4.2
Fix from $1,950 2026-07-01
Activemq HIGH 7.5
CVE-2026-50750

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-4…

Mitigation only
Fix from $1,950 2026-06-30
Cxf HIGH 7.5
CVE-2026-50645

There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncon…

Fix: 4.1.7 / 4.2.2+
Fix from $1,950 2026-06-12
Fluss HIGH 7.5
CVE-2026-49361

Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing un…

Fix: 0.9.1+
Fix from $1,950 2026-06-01
Thrift HIGH 7.3
CVE-2026-43870

Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in…

Fix: 0.23.0+
Fix from $1,950 2026-05-05
Neethi HIGH 7.5
CVE-2026-42403

Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (wher…

Fix: 3.2.2+
Fix from $1,950 2026-05-01
Neethi HIGH 7.5
CVE-2026-42402

Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documen…

Fix: 3.2.2+
Fix from $1,950 2026-05-01
Activemq HIGH 7.5
CVE-2026-39304

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do…

Fix: 5.19.4 / 6.2.4+
Fix from $1,950 2026-04-10
Cassandra MEDIUM 6.5
CVE-2026-32588

Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes. Users …

Fix: 4.0.20 / 4.1.11+
Fix from $1,600 2026-04-07
Iotdb HIGH 7.5
CVE-2025-48392

A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0.4. Users are recommended to…

Fix: 2.0.5+
Fix from $1,950 2025-09-24
Brpc HIGH 7.5
CVE-2025-54472

Unlimited memory allocation in redis protocol parser in Apache bRPC (all versions < 1.14.1) on all platforms allows attackers to crash the service vi…

Fix: 1.14.1+
Fix from $1,950 2025-08-14
Cxf MEDIUM 5.6
CVE-2025-48795

Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary …

Mitigation only
Fix from $1,600 2025-07-15
Tomcat HIGH 7.5
CVE-2025-53506

Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the …

Fix: after 11.0.8
Fix from $1,950 2025-07-10
Traffic Server HIGH 7.5
CVE-2025-49763

ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. …

Fix: 9.2.11 / 10.0.6+
Fix from $1,950 2025-06-19
Commons Configuration MEDIUM 6.5
CVE-2025-46392

Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of issues in Apache Commons Configuration 1.…

Fix: 2.0+
Fix from $1,600 2025-05-09