Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.3
CVE-2026-43869
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are re…
Thrift
0.23.0+
CRITICAL 9.9
CVE-2026-42809
Apache Polaris can issue broad temporary ("vended") storage credentials during
staged
table creation before the effective table location has been val…
Polaris
1.4.1+
CRITICAL 9.9
CVE-2026-42810
Apache Polaris accepts literal `*` characters in namespace and table names. When it
later builds temporary S3 access policies for delegated table acc…
Polaris
1.4.1+
CRITICAL 9.9
CVE-2026-42811
In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials
that
only work for one table's files, but a crafted namespace or tabl…
Polaris
1.4.1+
CRITICAL 9.9
CVE-2026-42812
In Apache Iceberg, the table's metadata files are control files: they tell readers
which data files belong to the table and which table version to re…
Polaris
1.4.1+
HIGH 7.5
CVE-2026-42440
OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader
Versions Affected:
before 1.9.5
before 2.5.9
before 3…
Opennlp
2.5.9+
CRITICAL 9.8
CVE-2026-42027
Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader
Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M…
Opennlp
2.5.9+
CRITICAL 9.1
CVE-2026-40682
XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor
Versions Affected: before 2.5.9, before 3.0…
Opennlp
2.5.9+
HIGH 8.1
CVE-2026-40563
Description:
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas
Apache Atlas exposes a DSL search endpoint that …
Atlas
2.5.0+
MEDIUM 6.5
CVE-2026-33523
HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.
This issue affects Apach…
HTTP Server
2.4.67+
MEDIUM 5.3
CVE-2026-33007
A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child p…
HTTP Server
2.4.67+
HIGH 8.8
CVE-2026-23918EPSS 50%
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.
This issue affects Apache HTTP Server: 2.4.66.
Users are…
HTTP Server
Mitigation only
HIGH 7.5
CVE-2026-29169
A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious reques…
HTTP Server
2.4.67+
MEDIUM 5.3
CVE-2026-33857
Out-of-bounds Read vulnerability in mod_proxy_ajp of
Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recomme…
HTTP Server
2.4.67+
MEDIUM 5.3
CVE-2026-34032
Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
Users are…
HTTP Server
2.4.67+
HIGH 8.8
CVE-2026-24072
An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges …
HTTP Server
2.4.67+
HIGH 7.5
CVE-2026-34059
Buffer Over-read vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to ve…
HTTP Server
2.4.67+
CRITICAL 9.8
CVE-2026-42778
The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description:
The fix for CVE-2024-52046 i…
Mina
2.1.12 / 2.2.7+
CRITICAL 9.8
CVE-2026-42779
The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description:
Apache MINA's Abstrac…
Mina
2.1.12 / 2.2.7+
HIGH 7.2
CVE-2026-42404
Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an appli…
Neethi
3.2.2+
HIGH 7.5
CVE-2026-42403
Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (wher…
Neethi
3.2.2+
HIGH 7.5
CVE-2026-42402
Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documen…
Neethi
3.2.2+
MEDIUM 5.9
CVE-2026-41016
Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performe…
Airflow
3.0.0+
CRITICAL 9.8
CVE-2026-41873
** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading t…
Pony Mail
Mitigation only
HIGH 8.2
CVE-2026-41604
Out-of-bounds Read vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.2…
Thrift
0.23.0+
HIGH 7.5
CVE-2026-41602
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation
This issue affects Apache Thrift: before 0…
Thrift
0.23.0+
HIGH 7.5
CVE-2026-41636
Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to up…
Thrift
0.23.0+
HIGH 7.4
CVE-2026-41603
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are re…
Thrift
0.23.0+
HIGH 7.3
CVE-2026-41605
Integer Overflow or Wraparound vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to…
Thrift
0.23.0+
MEDIUM 6.5
CVE-2026-41607
Out-of-bounds Read vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.2…
Thrift
0.23.0+