Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-48828
The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (…
Airflow
3.3.0+
MEDIUM 6.5
CVE-2026-48892
The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` …
Airflow
3.3.0+
MEDIUM 6.5
CVE-2026-49296
Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/…
Airflow
3.3.0+
MEDIUM 6.5
CVE-2026-49487
In Apache Airflow before 3.3.0, the REST API task-instance detail and list
endpoints returned a deferred task's trigger kwargs without masking. When …
Airflow
3.3.0+
CRITICAL 9.8
CVE-2026-33264
A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server …
Airflow
3.3.0+
HIGH 7.3
CVE-2026-43825EPSS 9%
Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel
Versions Affected:
before 3.0.0-M4 (libsvm document categorization module; introdu…
Opennlp
Mitigation only
HIGH 8.1
CVE-2026-49297
Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket …
Apache Airflow Providers Google
22.2.1+
HIGH 7.3
CVE-2026-49042
Improper Input Validation vulnerability in Apache Camel.
This issue affects Apache Camel: from 4.8.0 through 4.18.2, from 4.19.0 through 4.20.0.
Us…
Camel
4.18.3 / 4.21.0+
HIGH 7.3
CVE-2026-46587
Improper Input Validation vulnerability in Apache Camel.
This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 th…
Camel
4.14.8 / 4.18.3+
HIGH 7.3
CVE-2026-46588
Improper Input Validation vulnerability in Apache Camel.
This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 th…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.8
CVE-2026-56140
Improper Input Validation vulnerability in Apache Camel AWS SNS component.
The camel-aws2-sns component filters Camel headers through a component-s…
Camel
4.14.8 / 4.18.3+
HIGH 7.5
CVE-2026-55994
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…
Camel
4.18.3 / 4.21.0+
MEDIUM 5.3
CVE-2026-56139
Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Undertow Component.
The camel-undertow HTTP server consum…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.8
CVE-2026-53913
Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak C…
Camel
4.18.3 / 4.21.0+
HIGH 7.5
CVE-2026-55993
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…
Camel
4.14.8 / 4.18.3+
MEDIUM 6.5
CVE-2026-49086
Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel DAPR component.
The camel-dapr Dapr Pu…
Camel
4.14.8 / 4.18.3+
MEDIUM 6.5
CVE-2026-49097
Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache…
Camel
4.14.8 / 4.18.3+
MEDIUM 5.3
CVE-2026-49365
Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTTP component.
The camel-netty-http HTTP server co…
Camel
4.14.8 / 4.18.3+
MEDIUM 5.3
CVE-2026-48206
Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel JIRA component.
The camel-jira producers r…
Camel
4.14.8 / 4.18.3+
MEDIUM 5.3
CVE-2026-49098
Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache…
Camel
4.14.8 / 4.18.3+
MEDIUM 5.3
CVE-2026-49099
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass Through User-Controlled Key …
Camel
4.14.8 / 4.18.3+
CRITICAL 9.8
CVE-2026-48204
Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component.
The camel-mongodb-gridfs produce…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.1
CVE-2026-48203
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Fo…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.1
CVE-2026-48205
Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component.
The camel-dns producers read DNS operatio…
Camel
4.14.8 / 4.18.3+
HIGH 8.8
CVE-2026-46590
Deserialization of Untrusted Data vulnerability in Apache Camel PQC component.
The camel-pqc component persists post-quantum key metadata (KeyMetada…
Camel
4.18.3 / 4.21.0+
HIGH 8.2
CVE-2026-46591
Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component.
The camel-neo4j producer builds the C…
Camel
4.14.8 / 4.18.3+
HIGH 7.5
CVE-2026-46585
Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Component.
The camel-lucene produce…
Camel
4.14.8 / 4.18.3+
HIGH 7.5
CVE-2026-46592
Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP component.
The camel-cxf prod…
Camel
4.14.8 / 4.18.3+
HIGH 7.5
CVE-2026-46726
Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Cam…
Camel
4.14.8 / 4.18.3+
CRITICAL 9.8
CVE-2026-43867
Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component.
The camel-pqc component persists post-quantum key metadata (KeyMetada…
Camel
4.18.3 / 4.21.0+