Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.3 CVE-2026-43869 Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are re… Thrift 0.23.0+ Fix from $1,9502026-05-05 CRITICAL 9.9 CVE-2026-42809 Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been val… Polaris 1.4.1+ Fix from $2,3002026-05-04 CRITICAL 9.9 CVE-2026-42810 Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table acc… Polaris 1.4.1+ Fix from $2,3002026-05-04 CRITICAL 9.9 CVE-2026-42811 In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or tabl… Polaris 1.4.1+ Fix from $2,3002026-05-04 CRITICAL 9.9 CVE-2026-42812 In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re… Polaris 1.4.1+ Fix from $2,3002026-05-04 HIGH 7.5 CVE-2026-42440 OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader  Versions Affected:  before 1.9.5 before 2.5.9 before 3… Opennlp 2.5.9+ Fix from $1,9502026-05-04 CRITICAL 9.8 CVE-2026-42027 Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M… Opennlp 2.5.9+ Fix from $2,3002026-05-04 CRITICAL 9.1 CVE-2026-40682 XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0… Opennlp 2.5.9+ Fix from $2,3002026-05-04 HIGH 8.1 CVE-2026-40563 Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL search endpoint that … Atlas 2.5.0+ Fix from $1,9502026-05-04 MEDIUM 6.5 CVE-2026-33523 HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apach… HTTP Server 2.4.67+ Fix from $1,6002026-05-04 MEDIUM 5.3 CVE-2026-33007 A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child p… HTTP Server 2.4.67+ Fix from $1,6002026-05-04 HIGH 8.8 CVE-2026-23918EPSS 50% Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are… HTTP Server Mitigation only Fix from $1,9502026-05-04 HIGH 7.5 CVE-2026-29169 A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious reques… HTTP Server 2.4.67+ Fix from $1,9502026-05-04 MEDIUM 5.3 CVE-2026-33857 Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recomme… HTTP Server 2.4.67+ Fix from $1,6002026-05-04 MEDIUM 5.3 CVE-2026-34032 Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are… HTTP Server 2.4.67+ Fix from $1,6002026-05-04 HIGH 8.8 CVE-2026-24072 An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges … HTTP Server 2.4.67+ Fix from $1,9502026-05-04 HIGH 7.5 CVE-2026-34059 Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to ve… HTTP Server 2.4.67+ Fix from $1,9502026-05-04 CRITICAL 9.8 CVE-2026-42778 The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 i… Mina 2.1.12 / 2.2.7+ Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-42779 The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's Abstrac… Mina 2.1.12 / 2.2.7+ Fix from $2,3002026-05-01 HIGH 7.2 CVE-2026-42404 Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an appli… Neethi 3.2.2+ Fix from $1,9502026-05-01 HIGH 7.5 CVE-2026-42403 Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (wher… Neethi 3.2.2+ Fix from $1,9502026-05-01 HIGH 7.5 CVE-2026-42402 Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documen… Neethi 3.2.2+ Fix from $1,9502026-05-01 MEDIUM 5.9 CVE-2026-41016 Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performe… Airflow 3.0.0+ Fix from $1,6002026-04-30 CRITICAL 9.8 CVE-2026-41873 ** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading t… Pony Mail Mitigation only Fix from $2,3002026-04-28 HIGH 8.2 CVE-2026-41604 Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.2… Thrift 0.23.0+ Fix from $1,9502026-04-28 HIGH 7.5 CVE-2026-41602 Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0… Thrift 0.23.0+ Fix from $1,9502026-04-28 HIGH 7.5 CVE-2026-41636 Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0. Users are recommended to up… Thrift 0.23.0+ Fix from $1,9502026-04-28 HIGH 7.4 CVE-2026-41603 Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are re… Thrift 0.23.0+ Fix from $1,9502026-04-28 HIGH 7.3 CVE-2026-41605 Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to… Thrift 0.23.0+ Fix from $1,9502026-04-28 MEDIUM 6.5 CVE-2026-41607 Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.2… Thrift 0.23.0+ Fix from $1,6002026-04-28