Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-73634
Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violatio…
Struts
Fix unknown
HIGH 7.5
CVE-2026-73633
Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSO…
Struts
No fix yet
HIGH 7.5
CVE-2026-57819
Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, …
Cxf
3.6.12 / 4.1.8+
HIGH 7.5
CVE-2026-64958
An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with ma…
Cxf
3.6.12 / 4.1.8+
HIGH 7.5
CVE-2026-48834
Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
Unauthenticate…
Answer
2.0.2+
HIGH 8.6
CVE-2026-58182
The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state.
This issue affects Apache Traffic Serv…
Traffic Server
9.2.15 / 10.1.4+
HIGH 7.5
CVE-2026-65324
Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory.
This …
Traffic Server
9.2.15 / 10.1.4+
HIGH 7.5
CVE-2026-58151
Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control.
This issue affects Apache Traffic …
Traffic Server
9.2.15 / 10.1.4+
HIGH 7.5
CVE-2026-66299
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.
This issue affects Apache Tomcat: from 11.0.0-M20 through…
Tomcat
9.0.121 / 10.1.58+
HIGH 7.5
CVE-2026-66142
Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to …
Neethi
3.2.3+
HIGH 7.5
CVE-2026-66143
It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies…
Neethi
No fix yet
HIGH 7.5
CVE-2026-66144
Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of …
Neethi
3.2.3+
HIGH 7.5
CVE-2026-59173
Uncontrolled Resource Consumption vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from …
Traffic Server
9.2.14 / 10.1.3+
HIGH 7.5
CVE-2026-24012
Uncontrolled Resource Consumption vulnerability in Apache IoTDB.
Some interface fails to impose reasonable
limits on the time span and aggregation …
Iotdb
2.0.8+
HIGH 7.5
CVE-2026-54428
Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earl…
Httpcomponents Core
after 5.4.2
HIGH 7.5
CVE-2026-54399
Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlie…
Httpcomponents Core
after 5.4.2
HIGH 7.5
CVE-2026-50750
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Following the fix for CVE-2026-4…
Activemq
Mitigation only
HIGH 7.5
CVE-2026-50645
There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncon…
Cxf
4.1.7 / 4.2.2+
HIGH 7.5
CVE-2026-49361
Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing un…
Fluss
0.9.1+
HIGH 7.3
CVE-2026-43870
Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in…
Thrift
0.23.0+
HIGH 7.5
CVE-2026-42403
Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (wher…
Neethi
3.2.2+
HIGH 7.5
CVE-2026-42402
Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documen…
Neethi
3.2.2+
HIGH 7.5
CVE-2026-39304
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.
ActiveMQ NIO SSL transports do…
Activemq
5.19.4 / 6.2.4+
MEDIUM 6.5
CVE-2026-32588
Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes.
Users …
Cassandra
4.0.20 / 4.1.11+
HIGH 7.5
CVE-2025-48392
A vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0.4.
Users are recommended to…
Iotdb
2.0.5+
HIGH 7.5
CVE-2025-54472
Unlimited memory allocation in redis protocol parser in Apache bRPC (all versions < 1.14.1) on all platforms allows attackers to crash the service vi…
Brpc
1.14.1+
MEDIUM 5.6
CVE-2025-48795
Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary …
Cxf
Mitigation only
HIGH 7.5
CVE-2025-53506
Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the …
Tomcat
after 11.0.8
HIGH 7.5
CVE-2025-49763
ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted.
…
Traffic Server
9.2.11 / 10.0.6+
MEDIUM 6.5
CVE-2025-46392
Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x.
There are a number of issues in Apache Commons Configuration 1.…
Commons Configuration
2.0+