Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Thrift MEDIUM 5.3
CVE-2026-41606

Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version…

Fix: 0.23.0+
Fix from $1,600 2026-04-28
Thrift HIGH 7.5
CVE-2025-48431

Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Use…

Fix: 0.23.0+
Fix from $1,950 2026-04-28
Storm MEDIUM 6.5
CVE-2026-41081

Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Des…

Fix: 2.8.7+
Fix from $1,600 2026-04-27
Camel CRITICAL 10.0
CVE-2026-33453EPSS 6%

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's ca…

Fix: after 4.14.5
Fix from $2,300 2026-04-27
Camel HIGH 8.8
CVE-2026-27172

The ConsulRegistry in the camel-consul component (class org.apache.camel.component.consul.ConsulRegistry and its inner ConsulRegistryUtils.deserializ…

Fix: 4.14.6 / 4.18.1+
Fix from $1,950 2026-04-27
Mina CRITICAL 9.8
CVE-2026-41409

The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized …

Fix: 2.0.28 / 2.1.11+
Fix from $2,300 2026-04-27
Camel HIGH 8.8
CVE-2026-40858

The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.…

Fix: 4.14.7 / 4.18.2+
Fix from $1,950 2026-04-27
Camel HIGH 8.2
CVE-2026-40022

When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root conte…

Fix: 4.14.6 / 4.18.2+
Fix from $1,950 2026-04-27
Camel CRITICAL 9.4
CVE-2026-33454

The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterSt…

Fix: 4.14.6 / 4.18.1+
Fix from $2,300 2026-04-27
Camel CRITICAL 9.9
CVE-2026-40453

The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable…

Fix: 4.14.6 / 4.18.2+
Fix from $2,300 2026-04-27
Camel CRITICAL 9.8
CVE-2026-40860

JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessa…

Fix: 4.14.7 / 4.18.2+
Fix from $2,300 2026-04-27
Mina CRITICAL 9.8
CVE-2026-41635

Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at …

Fix: 2.0.28 / 2.1.11+
Fix from $2,300 2026-04-27
Camel HIGH 8.8
CVE-2026-40473

The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any…

Fix: 4.14.6 / 4.18.2+
Fix from $1,950 2026-04-27
Camel HIGH 7.8
CVE-2026-40048

The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using java.io.Objec…

Fix: 4.18.2+
Fix from $1,950 2026-04-27
Dolphinscheduler HIGH 8.1
CVE-2026-23902

Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not…

Fix: 3.4.1+
Fix from $1,950 2026-04-24
Activemq HIGH 8.8
CVE-2026-40466

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Ap…

Fix: 5.19.6 / 6.2.5+
Fix from $1,950 2026-04-24
Activemq HIGH 8.8
CVE-2026-41044

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache…

Fix: 5.19.6 / 6.2.5+
Fix from $1,950 2026-04-24
Activemq MEDIUM 6.5
CVE-2026-41043

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticate…

Fix: 5.19.6 / 6.2.5+
Fix from $1,600 2026-04-24
Dolphinscheduler MEDIUM 6.3
CVE-2025-62233

Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler:  Version >= 3.2.…

Fix: 3.3.1+
Fix from $1,600 2026-04-24
Httpclient HIGH 7.3
CVE-2026-40542

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication withou…

Mitigation only
Fix from $1,950 2026-04-22
Kafka MEDIUM 5.3
CVE-2026-33558

Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire requests and responses inform…

Fix: 3.9.2+
Fix from $1,600 2026-04-20
Kafka CRITICAL 9.1
CVE-2026-33557

A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set…

Fix: 4.1.2+
Fix from $2,300 2026-04-20
Doris Mcp Server MEDIUM 5.3
CVE-2025-66335

Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow executio…

Fix: 0.6.1+
Fix from $1,600 2026-04-20
Apache Airflow Providers Keycloak MEDIUM 5.4
CVE-2026-40948

The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login …

Fix: 0.7.0+
Fix from $1,600 2026-04-18
Airflow HIGH 8.8
CVE-2026-30898

An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be …

Fix: 3.2.0+
Fix from $1,950 2026-04-18
Airflow HIGH 7.5
CVE-2026-30912

In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to expo…

Fix: 3.2.0+
Fix from $1,950 2026-04-18
Airflow HIGH 7.5
CVE-2026-32228

UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that …

Fix: 3.2.0+
Fix from $1,950 2026-04-18
Airflow HIGH 7.2
CVE-2026-25917

Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbit…

Fix: 3.2.0+
Fix from $1,950 2026-04-18
Airflow HIGH 7.5
CVE-2026-31987

JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that…

Fix: 3.2.0+
Fix from $1,950 2026-04-16
Airflow MEDIUM 6.5
CVE-2026-25219

The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read p…

Fix: 3.2.0+
Fix from $1,600 2026-04-15