Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Thrift HIGH 7.3
CVE-2026-43869

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are re…

Fix: 0.23.0+
Fix from $1,950 2026-05-05
Polaris CRITICAL 9.9
CVE-2026-42809

Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been val…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Polaris CRITICAL 9.9
CVE-2026-42810

Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table acc…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Polaris CRITICAL 9.9
CVE-2026-42811

In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or tabl…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Polaris CRITICAL 9.9
CVE-2026-42812

In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Opennlp HIGH 7.5
CVE-2026-42440

OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader  Versions Affected:  before 1.9.5 before 2.5.9 before 3…

Fix: 2.5.9+
Fix from $1,950 2026-05-04
Opennlp CRITICAL 9.8
CVE-2026-42027

Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M…

Fix: 2.5.9+
Fix from $2,300 2026-05-04
Opennlp CRITICAL 9.1
CVE-2026-40682

XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0…

Fix: 2.5.9+
Fix from $2,300 2026-05-04
Atlas HIGH 8.1
CVE-2026-40563

Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL search endpoint that …

Fix: 2.5.0+
Fix from $1,950 2026-05-04
HTTP Server MEDIUM 6.5
CVE-2026-33523

HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apach…

Fix: 2.4.67+
Fix from $1,600 2026-05-04
HTTP Server MEDIUM 5.3
CVE-2026-33007

A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child p…

Fix: 2.4.67+
Fix from $1,600 2026-05-04
HTTP Server HIGH 8.8
CVE-2026-23918EPSS 50%

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are…

Mitigation only
Fix from $1,950 2026-05-04
HTTP Server HIGH 7.5
CVE-2026-29169

A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious reques…

Fix: 2.4.67+
Fix from $1,950 2026-05-04
HTTP Server MEDIUM 5.3
CVE-2026-33857

Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recomme…

Fix: 2.4.67+
Fix from $1,600 2026-05-04
HTTP Server MEDIUM 5.3
CVE-2026-34032

Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are…

Fix: 2.4.67+
Fix from $1,600 2026-05-04
HTTP Server HIGH 8.8
CVE-2026-24072

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges …

Fix: 2.4.67+
Fix from $1,950 2026-05-04
HTTP Server HIGH 7.5
CVE-2026-34059

Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to ve…

Fix: 2.4.67+
Fix from $1,950 2026-05-04
Mina CRITICAL 9.8
CVE-2026-42778

The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 i…

Fix: 2.1.12 / 2.2.7+
Fix from $2,300 2026-05-01
Mina CRITICAL 9.8
CVE-2026-42779

The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's Abstrac…

Fix: 2.1.12 / 2.2.7+
Fix from $2,300 2026-05-01
Neethi HIGH 7.2
CVE-2026-42404

Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an appli…

Fix: 3.2.2+
Fix from $1,950 2026-05-01
Neethi HIGH 7.5
CVE-2026-42403

Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (wher…

Fix: 3.2.2+
Fix from $1,950 2026-05-01
Neethi HIGH 7.5
CVE-2026-42402

Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documen…

Fix: 3.2.2+
Fix from $1,950 2026-05-01
Airflow MEDIUM 5.9
CVE-2026-41016

Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performe…

Fix: 3.0.0+
Fix from $1,600 2026-04-30
Pony Mail CRITICAL 9.8
CVE-2026-41873

** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading t…

Mitigation only
Fix from $2,300 2026-04-28
Thrift HIGH 8.2
CVE-2026-41604

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.2…

Fix: 0.23.0+
Fix from $1,950 2026-04-28
Thrift HIGH 7.5
CVE-2026-41602

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0…

Fix: 0.23.0+
Fix from $1,950 2026-04-28
Thrift HIGH 7.5
CVE-2026-41636

Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to up…

Fix: 0.23.0+
Fix from $1,950 2026-04-28
Thrift HIGH 7.4
CVE-2026-41603

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are re…

Fix: 0.23.0+
Fix from $1,950 2026-04-28
Thrift HIGH 7.3
CVE-2026-41605

Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to…

Fix: 0.23.0+
Fix from $1,950 2026-04-28
Thrift MEDIUM 6.5
CVE-2026-41607

Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.2…

Fix: 0.23.0+
Fix from $1,600 2026-04-28