Vulnerability index

Browse CVEs

207 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.8 CVE-2026-67587 Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the store… Airflow No fix yet Fix from $4,9002026-08-12 HIGH 7.3 CVE-2026-67260 Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deseria… Airflow No fix yet Fix from $4,9002026-08-12 MEDIUM 5.4 CVE-2026-59242 Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_v… Airflow 3.3.1+ Fix from $4,0002026-08-12 HIGH 8.8 CVE-2026-58076 Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and in… Airflow 3.3.1+ Fix from $4,9002026-08-12 CRITICAL 9.8 CVE-2026-71558 Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafte… Fory 1.5.0+ Fix from $2,3002026-08-07 CRITICAL 9.1 CVE-2026-71560 Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deser… Fory 1.5.0+ Fix from $2,3002026-08-07 HIGH 7.5 CVE-2026-71559 Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying … Fory 1.5.0+ Fix from $1,9502026-08-07 CRITICAL 9.8 CVE-2026-66909 Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in pla… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-61484 ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As th… Lucy No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-58163 Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: … Traffic Server 9.2.15 / 10.1.4+ Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-66713 Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0… Axis2\/java 2.0.1+ Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-64606 Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lamb… Fory 1.4.0+ Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-64608 Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip pa… Fory 1.4.0+ Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-33264 A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server … Airflow 3.3.0+ Fix from $2,3002026-07-07 HIGH 7.3 CVE-2026-43825EPSS 9% Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document categorization module; introdu… Opennlp Mitigation only Fix from $1,9502026-07-06 HIGH 8.8 CVE-2026-46590 Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-quantum key metadata (KeyMetada… Camel 4.18.3 / 4.21.0+ Fix from $1,9502026-07-06 CRITICAL 9.8 CVE-2026-43867 Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-quantum key metadata (KeyMetada… Camel 4.18.3 / 4.21.0+ Fix from $2,3002026-07-06 HIGH 8.1 CVE-2026-42527 Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components … Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 HIGH 8.1 CVE-2026-43865 Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component creates and manages Hazelcast ins… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 HIGH 8.1 CVE-2026-40859 Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP response bodies carrying the Conte… Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 HIGH 7.3 CVE-2026-43866 Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBinding.extractBodyFromJms() in camel-jms - and the … Camel 4.14.8 / 4.18.3+ Fix from $1,9502026-07-06 HIGH 8.1 CVE-2026-50632 A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, whi… Cxf 4.1.7 / 4.2.2+ Fix from $1,9502026-06-12 HIGH 8.1 CVE-2026-50633 A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able… Cxf 4.1.7 / 4.2.2+ Fix from $1,9502026-06-12 CRITICAL 9.1 CVE-2026-50076 Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remo… Fory 1.1.0+ Fix from $2,3002026-06-04 CRITICAL 9.8 CVE-2026-47065 ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the seri… Mina Mitigation only Fix from $2,3002026-06-03 HIGH 7.3 CVE-2026-45360 Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported and dispatched arbitrary clas… Airflow 3.2.2+ Fix from $1,9502026-06-01 HIGH 8.8 CVE-2026-42359 A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission on a … Airflow 3.2.2+ Fix from $1,9502026-06-01 CRITICAL 9.8 CVE-2026-48207 Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks dur… Fory 1.0.0+ Fix from $2,3002026-05-21 CRITICAL 9.8 CVE-2026-42027 Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M… Opennlp 2.5.9+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-42778 The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 i… Mina 2.1.12 / 2.2.7+ Fix from $2,3002026-05-01