Apache
693 known vulnerabilities
Top Products
Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at
Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attack
Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP se
Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking w
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that
Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security
Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as r
Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing t
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize req
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allow
Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a
Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated r
An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0
SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows
Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.1
Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through
Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Cam
Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel:
Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from
Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel:
Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Inject
Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Came
Improper input validation vulnerability in Apache Camel. This issue affects Apache Camel: from 2.17.0 before 4.14.9,
Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration fu
Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow
Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disclosure.
Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack
Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by def
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webhook module while lis
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent
Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant mani
Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functionality. Whe
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's
Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock User Functionality. Th
Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password func
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication pl
Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of t
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plug
Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database. Th
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plu
Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery
Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's U
SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-contro
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Cloud
Server-Side Request Forgery (SSRF) vulnerability in Apache InLong. Any authenticated user (no admin role required) can
Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem. This issue
Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the
Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorizati
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi
Frequently Asked Questions
How many CVEs affect Apache?
Apache has 693 CVE records in our database, including 142 critical and 305 high severity vulnerabilities. 2 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apache vulnerabilities?
Apache has 142 critical severity (CVSS 9.0+) and 305 high severity (CVSS 7.0-8.9) vulnerabilities. 2 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apache vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apache Vulnerabilities
CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.
Get Started