Apache
2,099 known vulnerabilities
Top Products
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of
Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim che
Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map witho
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` val
A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via c
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, wit
Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. Ho
An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF
Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" co
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in th
Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.
Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenti
Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Admin
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache An
Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authentica
Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing
Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: throug
Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: t
** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Luc
** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue af
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apac
** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: al
It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated atta
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni
pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential d
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni
Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding
Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts throu
Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization
Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients wit
Frequently Asked Questions
How many CVEs affect Apache?
Apache has 2,099 CVE records in our database, including 281 critical and 645 high severity vulnerabilities. 14 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apache vulnerabilities?
Apache has 281 critical severity (CVSS 9.0+) and 645 high severity (CVSS 7.0-8.9) vulnerabilities. 14 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apache vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apache Vulnerabilities
CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.
Get Started