Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Apache

693 known vulnerabilities

141
CRITICAL
292
HIGH
226
MEDIUM
11
LOW

Top Products

airflow 61 camel 55 traffic server 41 tomcat 40 cloudstack 27 cxf 26 thrift 25 activemq 24 http server 24 ofbiz 19
670 CVEs · Page 1/14
7.5
CVE-2026-75005

Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at

8.8
CVE-2026-63041

Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attack

6.8
CVE-2026-73180

Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP se

7.5
CVE-2026-68763

Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking w

8.1
CVE-2026-68569

Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that

9.1
CVE-2026-68525

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security

8.1
CVE-2026-66422

Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as r

7.5
CVE-2026-65927

Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing t

9.8
CVE-2026-65905

Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize req

9.8
CVE-2026-65637

Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects

8.1
CVE-2026-65183

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allow

9.1
CVE-2026-65182

Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a

9.1
CVE-2026-55976

Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated r

7.4
CVE-2026-53561

An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0

9.8
CVE-2026-49845

SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows

9.8
CVE-2026-78329

Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.1

5.3
CVE-2026-75099

Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through

9.8
CVE-2026-71300

Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Cam

7.5
CVE-2026-66908

Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel:

7.5
CVE-2026-66907

Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from

9.1
CVE-2026-66906

Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel:

5.3
CVE-2026-63621

Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Inject

5.5
CVE-2026-60093

Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Came

6.5
CVE-2026-59230

Improper input validation vulnerability in Apache Camel. This issue affects Apache Camel: from 2.17.0 before 4.14.9,

7.5
CVE-2026-59654

Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration fu

8.1
CVE-2026-68745

Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow

5.4
CVE-2026-66797

Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disclosure.

7.2
CVE-2026-66722

Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack

2.7
CVE-2026-66721

Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by def

4.3
CVE-2026-65613

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webhook module while lis

8.8
CVE-2026-63046

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent

9.1
CVE-2026-62440

Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant mani

4.3
CVE-2026-61422

Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functionality. Whe

8.8
CVE-2026-61400

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's

4.8
CVE-2026-61399

Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock User Functionality. Th

9.1
CVE-2026-61398

Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password func

7.5
CVE-2026-61397

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication pl

8.8
CVE-2026-59799

Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of t

7.5
CVE-2026-59780

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plug

7.5
CVE-2026-59657

Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database. Th

7.5
CVE-2026-59655

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plu

9.1
CVE-2026-59085

Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery

7.5
CVE-2026-50222

Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's U

8.8
CVE-2026-50112

SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-contro

8.8
CVE-2026-47359

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Cloud

5.4
CVE-2026-63044

Server-Side Request Forgery (SSRF) vulnerability in Apache InLong.  Any authenticated user (no admin role required) can

7.5
CVE-2026-63043

Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem. This issue

8.1
CVE-2026-63042

Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the

8.1
CVE-2026-63040

Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorizati

9.8
CVE-2026-63039

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi

Frequently Asked Questions

How many CVEs affect Apache?

Apache has 693 CVE records in our database, including 142 critical and 305 high severity vulnerabilities. 2 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Apache vulnerabilities?

Apache has 142 critical severity (CVSS 9.0+) and 305 high severity (CVSS 7.0-8.9) vulnerabilities. 2 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Apache vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Apache Vulnerabilities

CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.

Get Started