Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Airflow MEDIUM 6.5
CVE-2026-48828

The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (…

Fix: 3.3.0+
Fix from $1,600 2026-07-07
Airflow MEDIUM 6.5
CVE-2026-48892

The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` …

Fix: 3.3.0+
Fix from $1,600 2026-07-07
Airflow MEDIUM 6.5
CVE-2026-49296

Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/…

Fix: 3.3.0+
Fix from $1,600 2026-07-07
Airflow MEDIUM 6.5
CVE-2026-49487

In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When …

Fix: 3.3.0+
Fix from $1,600 2026-07-07
Airflow CRITICAL 9.8
CVE-2026-33264

A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server …

Fix: 3.3.0+
Fix from $2,300 2026-07-07
Opennlp HIGH 7.3
CVE-2026-43825EPSS 9%

Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document categorization module; introdu…

Mitigation only
Fix from $1,950 2026-07-06
Apache Airflow Providers Google HIGH 8.1
CVE-2026-49297

Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket …

Fix: 22.2.1+
Fix from $1,950 2026-07-06
Camel HIGH 7.3
CVE-2026-49042

Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: from 4.8.0 through 4.18.2, from 4.19.0 through 4.20.0. Us…

Fix: 4.18.3 / 4.21.0+
Fix from $1,950 2026-07-06
Camel HIGH 7.3
CVE-2026-46587

Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 th…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel HIGH 7.3
CVE-2026-46588

Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 th…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel CRITICAL 9.8
CVE-2026-56140

Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel headers through a component-s…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Camel HIGH 7.5
CVE-2026-55994

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…

Fix: 4.18.3 / 4.21.0+
Fix from $1,950 2026-07-06
Camel MEDIUM 5.3
CVE-2026-56139

Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Undertow Component. The camel-undertow HTTP server consum…

Fix: 4.14.8 / 4.18.3+
Fix from $1,600 2026-07-06
Camel CRITICAL 9.8
CVE-2026-53913

Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak C…

Fix: 4.18.3 / 4.21.0+
Fix from $2,300 2026-07-06
Camel HIGH 7.5
CVE-2026-55993

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel MEDIUM 6.5
CVE-2026-49086

Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel DAPR component. The camel-dapr Dapr Pu…

Fix: 4.14.8 / 4.18.3+
Fix from $1,600 2026-07-06
Camel MEDIUM 6.5
CVE-2026-49097

Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache…

Fix: 4.14.8 / 4.18.3+
Fix from $1,600 2026-07-06
Camel MEDIUM 5.3
CVE-2026-49365

Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTTP component. The camel-netty-http HTTP server co…

Fix: 4.14.8 / 4.18.3+
Fix from $1,600 2026-07-06
Camel MEDIUM 5.3
CVE-2026-48206

Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel JIRA component. The camel-jira producers r…

Fix: 4.14.8 / 4.18.3+
Fix from $1,600 2026-07-06
Camel MEDIUM 5.3
CVE-2026-49098

Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache…

Fix: 4.14.8 / 4.18.3+
Fix from $1,600 2026-07-06
Camel MEDIUM 5.3
CVE-2026-49099

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass Through User-Controlled Key …

Fix: 4.14.8 / 4.18.3+
Fix from $1,600 2026-07-06
Camel CRITICAL 9.8
CVE-2026-48204

Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs produce…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.1
CVE-2026-48203

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Fo…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.1
CVE-2026-48205

Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dns producers read DNS operatio…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Camel HIGH 8.8
CVE-2026-46590

Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-quantum key metadata (KeyMetada…

Fix: 4.18.3 / 4.21.0+
Fix from $1,950 2026-07-06
Camel HIGH 8.2
CVE-2026-46591

Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component. The camel-neo4j producer builds the C…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel HIGH 7.5
CVE-2026-46585

Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Component. The camel-lucene produce…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel HIGH 7.5
CVE-2026-46592

Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP component. The camel-cxf prod…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel HIGH 7.5
CVE-2026-46726

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…

Fix: 4.14.8 / 4.18.3+
Fix from $1,950 2026-07-06
Camel CRITICAL 9.8
CVE-2026-43867

Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-quantum key metadata (KeyMetada…

Fix: 4.18.3 / 4.21.0+
Fix from $2,300 2026-07-06