CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-103413 - Improper input validation vulnerability in Apache Camel Karavan. When a deployment was started, K
CVE-2026-103412 - Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Apac
CVE-2026-97791 - In Apache CXF, STSTokenValidator checks whether a SAML assertion is signed by a trusted certificate
CVE-2026-97468 - Apache CXF's STSTokenValidator and Security Token Service (STS) cached validated security tokens und
CVE-2026-86463 - Apache CXF's FIQL query parser has a vulnerability in how it searches for operators in query express
CVE-2026-79650 - Apache CXF’s OIDC relying-party component could redirect users to an attacker-controlled URL after s
CVE-2026-78384 - CompressionUtils.inflate() decompressed attacker-controlled DEFLATE data with no output-size cap. A
CVE-2026-73179 - Improper enforcement of single-use authorization code semantics in the JPA OAuth2 authorization code
CVE-2026-108039 - By default, StaxUtils placed no limit on the total number of elements or the total number of charact
CVE-2026-107938 - In Apache CXF, the Netty-based HTTP client transport (cxf-rt-transports-http-netty-client) did not v
CVE-2026-107937 - In Apache CXF, the parser for multipart/MTOM attachment part headers did not fully enforce the confi
CVE-2026-100227 - Improper Verification of Cryptographic Signature vulnerability in Apache CXF's JAX-RS XML Security m
CVE-2026-55976 - Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allow
CVE-2026-53561 - An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive
CVE-2026-49845 - SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on
CVE-2026-49050 - General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinSch
CVE-2026-56096 - The extension passes the user-supplied search query parameter to Apache Solr without restricting adv
CVE-2026-78329 - Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Ap
CVE-2026-75099 - Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apa
CVE-2026-71300 - Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issu
CVE-2026-66908 - Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue af
CVE-2026-66907 - Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affect
CVE-2026-66906 - Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue af
CVE-2026-63621 - Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstrea
CVE-2026-60093 - Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue
CVE-2026-59230 - Improper input validation vulnerability in Apache Camel. This issue affects Apache Camel: from 2.
CVE-2026-19565 - Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication
CVE-2026-54789 - mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x H
CVE-2026-59654 - Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped glo
CVE-2026-68745 - Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on
CVE-2026-66797 - Improper access control in CloudStack's annotation functionality allows unauthorized comment creatio
CVE-2026-66722 - Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain
CVE-2026-66721 - Missing authorization issue for domain admins in CloudStack's host tags listing functionality. D
CVE-2026-65613 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webh
CVE-2026-63046 - Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in
CVE-2026-62440 - Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowi
CVE-2026-61422 - Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration
CVE-2026-61400 - Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in
CVE-2026-61399 - Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock Use
CVE-2026-61398 - Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance
CVE-2026-61397 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAut
CVE-2026-59799 - Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin
CVE-2026-59780 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP
CVE-2026-59657 - Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage
CVE-2026-59655 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAut
CVE-2026-59085 - Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable
CVE-2026-50222 - Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A
CVE-2026-50112 - SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing t
CVE-2026-47359 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi
CVE-2026-65770 - Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed
CVE-2026-63044 - Server-Side Request Forgery (SSRF) vulnerability in Apache InLong. Any authenticated user (no admin
CVE-2026-63043 - Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host file
CVE-2026-63042 - Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can
CVE-2026-63040 - Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource per
CVE-2026-63039 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-63038 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-63037 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-63016 - Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational con
CVE-2026-63015 - Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons c
CVE-2026-63408 - Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's cont
CVE-2026-62673 - Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess
CVE-2026-18051 - The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it use
CVE-2026-34884 - SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking
CVE-2026-19349 - Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 befo
CVE-2026-19728 - The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify th
CVE-2026-73635 - Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed l
CVE-2026-73634 - Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an end
CVE-2026-73632 - Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-res
CVE-2026-73631 - Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-req
CVE-2026-73633 - Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an applica
CVE-2026-73649 - Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, t
CVE-2026-18428 - A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allo
CVE-2026-66256 - ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig.
CVE-2026-73240 - Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects
CVE-2026-73239 - Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types
CVE-2026-73238 - XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1
CVE-2026-73237 - XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.1
CVE-2026-68971 - Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and t
CVE-2026-68970 - Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so sec
CVE-2026-68969 - Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext w
CVE-2026-68968 - Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever
CVE-2026-68076 - Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable
CVE-2026-67587 - Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constru
CVE-2026-67260 - Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task
CVE-2026-65017 - Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team de
CVE-2026-59244 - Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the
CVE-2026-59242 - Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a strin
CVE-2026-58076 - Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a
CVE-2026-54183 - Apache Airflow's secrets masker hides values stored under sensitive key names when they are displaye
CVE-2026-68868 - The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied th
CVE-2026-71290 - Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. Hostn
CVE-2026-13457 - The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Co
CVE-2026-69223 - Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects A
CVE-2026-68872 - The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon prov
CVE-2026-68871 - The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connec
CVE-2026-68870 - The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-sco
CVE-2026-65948 - UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0. Note: UnixAuth is NOT a
CVE-2026-65945 - Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgra
CVE-2026-65942 - TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recomme
CVE-2026-61899 - Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to downlo
CVE-2026-55814 - Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to
CVE-2026-55799 - Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are
CVE-2026-44416 - Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apach
CVE-2026-42537 - Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgr
CVE-2026-40920 - Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are re
CVE-2026-32227 - SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recomme
CVE-2026-28672 - Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in
CVE-2026-44630 - Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthentica
CVE-2026-71560 - Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory
CVE-2026-71559 - Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an at
CVE-2026-71558 - Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache For
CVE-2026-63725 - sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around
CVE-2026-34502 - Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This i
CVE-2026-34501 - Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issu
CVE-2026-34191 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-68481 - In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully
CVE-2026-68079 - In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an
CVE-2026-65583 - Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcin
CVE-2026-63687 - Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization
CVE-2026-61466 - In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and st
CVE-2026-66909 - Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java
CVE-2026-65432 - Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and e
CVE-2026-64958 - An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service
CVE-2026-57819 - Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFo
CVE-2026-57817 - The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter
CVE-2026-54225 - Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apa
CVE-2026-64640 - Apache Polaris did not consistently validate storage locations supplied during table and view regist
CVE-2026-60053 - Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: t
CVE-2026-60023 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This iss
CVE-2026-50749 - Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.
CVE-2026-48912 - Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through
CVE-2026-48911 - Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects A
CVE-2026-48834 - Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affe
CVE-2026-61486 - ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This is
CVE-2026-61484 - ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. T
CVE-2026-61483 - ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue a
CVE-2026-68080 - It was not possible to govern the rate at which the broker would respond to an echo flow, enabling a
CVE-2026-68078 - It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling
CVE-2026-68077 - An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessi
CVE-2026-68075 - An authenticated attacker could exceed the session flow control incoming window potentially leading
CVE-2026-68073 - A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially
CVE-2026-67592 - It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling
CVE-2026-67591 - An authenticated attacker could exceed the session flow control incoming window potentially leading
CVE-2026-67590 - A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially
CVE-2026-67555 - It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling
CVE-2026-67554 - An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessi
CVE-2026-67553 - An authenticated attacker could exceed the session flow control incoming window potentially leading
CVE-2026-67552 - A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially
CVE-2026-66277 - It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling
CVE-2026-66276 - An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessi
CVE-2026-66275 - An authenticated attacker could exceed the session flow control incoming window potentially leading
CVE-2026-66274 - A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially
CVE-2026-16993 - The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping
CVE-2026-68074 - A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaus
CVE-2026-68060 - A pre-authentication attacker could leverage type size/count handling to cause excessive allocation
CVE-2026-67589 - A pre-authentication attacker could leverage type size/count handling to cause excessive allocation
CVE-2026-67588 - A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaus
CVE-2026-67551 - pre-authentication attacker could leverage type size/count handling to cause excessive allocation le
CVE-2026-67465 - A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaus
CVE-2026-66273 - A pre-authentication attacker could leverage type size/count handling to cause excessive allocation
CVE-2026-66257 - A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaus
CVE-2026-68981 - Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API usi
CVE-2026-68980 - Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Para
CVE-2026-68979 - Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not e
CVE-2026-62354 - Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.
CVE-2026-61372 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac
CVE-2026-67609 - Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a
CVE-2026-67608 - Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a
CVE-2026-64607 - HttpClient based on the classic i/o model fails to correctly release the underlying connection back
CVE-2026-62391 - The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server
CVE-2026-44615 - Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authe
CVE-2026-66756 - Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika:
CVE-2026-66755 - Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 thr
CVE-2026-52680 - Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when
CVE-2026-48910 - A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsi
CVE-2026-44617 - LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name e
CVE-2026-44616 - LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search f
CVE-2026-44613 - Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration a
CVE-2026-28814 - Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows
CVE-2026-28813 - Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities.
CVE-2026-28812 - UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attac
CVE-2026-28811 - Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommend
CVE-2026-23985 - A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.
CVE-2026-23981 - An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user wit
CVE-2026-65100 - Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block enco
CVE-2026-59243 - The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID
CVE-2026-58189 - Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SS
CVE-2026-58188 - Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. Th
CVE-2026-58187 - The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, ena
CVE-2026-58186 - The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable
CVE-2026-58185 - The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffi
CVE-2026-58184 - The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations
CVE-2026-58183 - The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. Th
CVE-2026-58182 - The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instan
CVE-2026-58181 - The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker
CVE-2026-58180 - The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This
CVE-2026-58179 - The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution inpu
CVE-2026-58178 - The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs.
CVE-2026-58177 - The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-f
CVE-2026-58175 - Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Tr
CVE-2026-58164 - Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration
CVE-2026-58163 - Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or cras
CVE-2026-58162 - The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled clien
CVE-2026-58161 - Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handli
CVE-2026-58160 - Apache Traffic Server reads out of bounds while parsing DNS answers. This issue affects Apache Tr
CVE-2026-58159 - Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors
CVE-2026-58158 - Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack.
CVE-2026-58157 - Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client
CVE-2026-50622 - Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache
CVE-2026-23904 - Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to th
CVE-2026-65325 - Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server cert
CVE-2026-65324 - Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, le
CVE-2026-58156 - Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypa
CVE-2026-58155 - Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling,
CVE-2026-58154 - Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP heade
CVE-2026-58153 - Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked frami
CVE-2026-58152 - Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory.
CVE-2026-58151 - Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and
CVE-2026-58150 - Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade reque
CVE-2026-57834 - Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affe
CVE-2026-41920 - Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic S
CVE-2026-33930 - Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound d
CVE-2026-33267 - Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic
CVE-2026-24033 - Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Ap
CVE-2026-22068 - Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apach
CVE-2026-67178 - MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrec
CVE-2026-66713 - Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache So
CVE-2026-66299 - Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This iss
CVE-2026-61487 - Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ
CVE-2026-59878 - Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ Al
CVE-2026-66391 - Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. T
CVE-2026-66390 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-66053 - Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings
CVE-2026-58662 - Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrif
CVE-2026-58389 - Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings.
CVE-2026-58023 - Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift
CVE-2026-55971 - Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache T
CVE-2026-55970 - Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: bef
CVE-2026-55969 - Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Ha
CVE-2026-55968 - Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerabili
CVE-2026-49158 - Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby
CVE-2026-48586 - Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++,
CVE-2026-48145 - Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings.
CVE-2026-48144 - Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings
CVE-2026-45112 - Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.
CVE-2026-43871 - Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PH
CVE-2026-41608 - Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Pyth
CVE-2026-49326 - Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan oper
CVE-2026-66143 - It is possible to bypass the maximum number of normalized policy alternatives that was introduced in
CVE-2026-66142 - Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware