CVE-2026-92550Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder Exploitation status Not known exploited Fix YesAffected product A Apache Qpid Broker-J Published 09/25/2026 Severity High CVE-2026-92560Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder Exploitation status Not known exploited Fix YesAffected product A Apache Qpid Broker-J Published 09/25/2026 Severity High CVE-2026-92573Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering Exploitation status Not known exploited Fix YesAffected product A Apache Qpid Broker-J Published 09/25/2026 Severity Medium CVE-2026-92564Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing Exploitation status Not confirmed Fix YesAffected product A Apache Qpid Broker-J Published 09/25/2026 Severity Unknown CVE-2026-92608Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10 Exploitation status Not known exploited Fix YesAffected product A Apache Qpid Broker-J Published 09/25/2026 Severity High CVE-2026-92609Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication Exploitation status Not known exploited Fix YesAffected product A Apache Qpid Broker-J Published 09/25/2026 Severity Critical CVE-2026-97636Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled key Exploitation status Not known exploited Fix YesAffected product A Apache Airflow HashiCorp provider Published 09/24/2026 Severity Medium CVE-2026-57590Apache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unauthorized Cross-Project Operations Exploitation status Not known exploited Fix YesAffected product A Apache DolphinScheduler Published 09/24/2026 Severity High CVE-2026-86247Apache Tomcat Native: Client certificate requirements can be down-graded Exploitation status Not known exploited Fix YesAffected product A Apache Tomcat Native Published 09/23/2026 Severity High CVE-2026-86246Apache Tomcat Native: Insecure OpenSSL options enabled Exploitation status Not known exploited Fix YesAffected product A Apache Tomcat Native Published 09/23/2026 Severity Critical CVE-2026-86243Apache Tomcat Native: DoS via TLS handshake Exploitation status Not known exploited Fix YesAffected product A Apache Tomcat Native Published 09/23/2026 Severity High CVE-2026-87022Apache Tomcat: WebSocket message smuggling with per-message-deflate Exploitation status Not known exploited Fix YesAffected product A Apache Tomcat Published 09/23/2026 Severity High CVE-2026-86350Apache Tomcat: Regression in fix for CVE-2026-41293 can trigger request header mix-up Exploitation status Not known exploited Fix YesAffected product A Apache Tomcat Published 09/23/2026 Severity Critical CVE-2026-86248Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled Exploitation status Not known exploited Fix YesAffected product A Apache Tomcat Published 09/23/2026 Severity Critical CVE-2026-79677Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout Exploitation status Not known exploited Fix YesAffected product A Apache Tomcat Published 09/23/2026 Severity High CVE-2026-78437Apache Tomcat: HTTP/2 DoS via malformed request Exploitation status Not known exploited Fix YesAffected product A Apache Tomcat Published 09/23/2026 Severity High CVE-2026-78383Apache Tomcat: AJP DoS via missing request body Exploitation status Not known exploited Fix YesAffected product A Apache Tomcat Published 09/23/2026 Severity High CVE-2026-77791Apache Tomcat: DoS via busy wait during WebSocket close Exploitation status Not known exploited Fix YesAffected product A Apache Tomcat Published 09/23/2026 Severity High CVE-2026-77762Apache Tomcat: Stale HPACK emitter injects trailers into recycled pooled Request Exploitation status Not known exploited Fix YesAffected product A Apache Tomcat Published 09/23/2026 Severity High CVE-2026-77756Apache Tomcat: Transfer-Encoding honored for HTTP/1.0 requests Exploitation status Not known exploited Fix YesAffected product A Apache Tomcat Published 09/23/2026 Severity Low CVE-2026-76183Apache Tomcat: Bypass of security constraints for WebSocket endpoints Exploitation status Not known exploited Fix YesAffected product A Apache Tomcat Published 09/23/2026 Severity Critical CVE-2026-75973Apache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configured Exploitation status Not known exploited Fix YesAffected product A Apache Tomcat Published 09/23/2026 Severity High CVE-2026-73581Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore Exploitation status Not known exploited Fix YesAffected product A Apache Tomcat Published 09/23/2026 Severity Medium CVE-2026-94243Apache Sling Security Bundle: RefererFilter accepts weaker-than-origin evidence Exploitation status Not known exploited Fix YesAffected product A Apache Sling Security Bundle Published 09/23/2026 Severity High CVE-2026-94251Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource Exploitation status Not known exploited Fix YesAffected product A Apache Sling Security Bundle Published 09/23/2026 Severity Medium CVE-2026-91928Apache Sling XSS: Sanitizer bypass, uncontrolled resource consumption and failure pf protection mechanisms Exploitation status Not known exploited Fix YesAffected product A Apache Sling XSS Published 09/23/2026 Severity Medium CVE-2026-96443Apache Doris: JDBC driver URL validation bypass leads to remote code execution Exploitation status Not known exploited Fix YesAffected product A Apache Doris Published 09/23/2026 Severity Medium CVE-2026-91852Apache Sling XSS: CWE-79 multiple raw-string break-outs and ReDOS in XSSImpl Exploitation status Not known exploited Fix YesAffected product A Apache Sling XSS Published 09/23/2026 Severity Medium CVE-2026-91999Apache Sling XSS: Improper escaping in the XSS Webconsole plugin Exploitation status Not known exploited Fix YesAffected product A Apache Sling XSS Published 09/23/2026 Severity Medium CVE-2026-92001Apache Sling XSS: Missing parser resource limits Exploitation status Not known exploited Fix YesAffected product A Apache Sling XSS Published 09/23/2026 Severity Medium CVE-2026-73192Apache Sling XSS: XSS possible through XSSAPI.getValidHref() Exploitation status Not known exploited Fix YesAffected product A Apache Sling XSS Published 09/23/2026 Severity Medium CVE-2026-31377Apache Doris: Improper Authentication Allows Unauthorized Access to FE Meta Service Exploitation status Not known exploited Fix YesAffected product A Apache Doris Published 09/23/2026 Severity High CVE-2026-82331Apache BuildStream: tar source extraction escape Exploitation status Not known exploited Fix YesAffected product A Apache BuildStream Published 09/23/2026 Severity Critical CVE-2026-70410Apache Calcite Avatica: Unrestricted class initialization when instantiating plugins Exploitation status Not known exploited Fix YesAffected product A Apache Calcite Avatica Published 09/22/2026 Severity High CVE-2026-94301Apache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.X branches (2.0.30 / 2.1.14) ZDRES-232 Exploitation status Not known exploited Fix YesAffected product A Apache MINA Published 09/21/2026 Severity Critical CVE-2026-86473Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocable only by expiry Exploitation status Not known exploited Fix YesAffected product A Apache Airflow Published 09/21/2026 Severity Critical CVE-2026-75158Apache Airflow: Assets events API returns asset events for every Dag with no per-Dag authorization filter Exploitation status Not known exploited Fix YesAffected product A Apache Airflow Published 09/21/2026 Severity Medium CVE-2026-82355Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, enabling session fixation Exploitation status Not known exploited Fix YesAffected product A Apache Airflow Published 09/21/2026 Severity Medium CVE-2026-91867Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitely Exploitation status Not known exploited Fix YesAffected product A Apache Neethi Published 09/21/2026 Severity Medium CVE-2026-91866Apache Neethi: Crafted policies cause unbounded work during intersection leading to denial of service Exploitation status Not known exploited Fix YesAffected product A Apache Neethi Published 09/21/2026 Severity High CVE-2026-91865Apache Neethi: Crafted policy references cause exponential expansion during normalization leading to denial of service Exploitation status Not known exploited Fix YesAffected product A Apache Neethi Published 09/21/2026 Severity High CVE-2026-91864Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustion Exploitation status Not known exploited Fix YesAffected product A Apache Neethi Published 09/21/2026 Severity High CVE-2026-91863Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows denial of service Exploitation status Not known exploited Fix YesAffected product A Apache Neethi Published 09/21/2026 Severity High CVE-2026-47321Apache MINA: Unbounded Decompression Amplification DoS in Zlib.inflate Exploitation status Not known exploited Fix YesAffected product A Apache MINA Published 09/21/2026 Severity High CVE-2026-75157Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDIT (asset-triggered scheduling suppression) Exploitation status Not known exploited Fix YesAffected product A Apache Airflow Published 09/18/2026 Severity High CVE-2026-92230Apache Karaf: Improper release of ClassLoader references via static ThreadLocal caching Exploitation status Not known exploited Fix YesAffected product A Apache Karaf Published 09/17/2026 Severity High CVE-2026-70469Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests Exploitation status Not known exploited Fix Not confirmed Affected product A Apache NiFi Published 09/16/2026 Severity High CVE-2026-81866Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration Exploitation status Not known exploited Fix YesAffected product A Apache NiFi Published 09/16/2026 Severity Low CVE-2026-82561Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods Exploitation status Not known exploited Fix YesAffected product A Apache NiFi Published 09/16/2026 Severity Medium CVE-2026-86089Apache NiFi: Missing Process Group Authorization for Connector Migration Exploitation status Not known exploited Fix Not confirmed Affected product A Apache NiFi Published 09/16/2026 Severity Low CVE-2026-87976Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles Exploitation status Not known exploited Fix YesAffected product A Apache NiFi Registry Published 09/16/2026 Severity High CVE-2026-76646Apache MyFaces: Denial of Service via Unbounded Request Parsing Exploitation status Not known exploited Fix YesAffected product A Apache MyFaces Published 09/16/2026 Severity High CVE-2026-68536Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability Exploitation status Not known exploited Fix YesAffected product A Apache MyFaces Published 09/16/2026 Severity Critical CVE-2026-84501Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationProvider Exploitation status Not known exploited Fix YesAffected product A Apache ZooKeeper Published 09/16/2026 Severity Medium CVE-2026-84439Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources Exploitation status Not known exploited Fix YesAffected product A Apache ZooKeeper Published 09/16/2026 Severity Medium CVE-2026-79993Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znode Exploitation status Not known exploited Fix YesAffected product A Apache ZooKeeper Published 09/16/2026 Severity High CVE-2026-59969Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode Exploitation status Not known exploited Fix YesAffected product A Apache ZooKeeper Published 09/16/2026 Severity High CVE-2026-59739Apache ZooKeeper: Information disclosure via SetWatches reconnect replay Exploitation status Not known exploited Fix YesAffected product A Apache ZooKeeper Published 09/16/2026 Severity High CVE-2026-86466Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validated Exploitation status Not known exploited Fix YesAffected product A Apache Airflow FAB provider Published 09/16/2026 Severity High CVE-2026-76187Apache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session JWT Exploitation status Not known exploited Fix YesAffected product A Apache Airflow Keycloak provider Published 09/16/2026 Severity Critical CVE-2026-76186Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity Exploitation status Not known exploited Fix YesAffected product A Apache Airflow Keycloak provider Published 09/16/2026 Severity Critical CVE-2026-82310Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access Exploitation status Not known exploited Fix YesAffected product A Apache Airflow FAB provider Published 09/16/2026 Severity High CVE-2026-86792Apache Airflow Apache Kafka provider: Connection-editor remote code execution on the Scheduler via Kafka connection callback configuration Exploitation status Not known exploited Fix YesAffected product A Apache Airflow Apache Kafka provider Published 09/16/2026 Severity High CVE-2026-86462Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessions Exploitation status Not known exploited Fix YesAffected product A Apache Airflow FAB provider Published 09/16/2026 Severity Critical CVE-2026-82311Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int _user_id comparison is always false Exploitation status Not known exploited Fix YesAffected product A Apache Airflow FAB provider Published 09/16/2026 Severity Critical CVE-2026-86465Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard bypass via user-controlled key Exploitation status Not known exploited Fix YesAffected product A Apache Airflow Akeyless provider Published 09/16/2026 Severity Medium CVE-2026-82427Apache Storm Nimbus: Path Traversal as the Supervisor User via Unsanitised Blobstore Map Local Name Exploitation status Not known exploited Fix YesAffected product A Apache Storm Nimbus Published 09/14/2026 Severity High CVE-2026-82428Apache Storm Client: Cross-Tenant Dependency Jar Substitution via Predictable Blob Keys Exploitation status Not known exploited Fix YesAffected product A Apache Storm Client Published 09/14/2026 Severity High CVE-2026-82429Apache Storm Worker Launcher: Local Privilege Escalation to Root via a Time-of-Check Race in the Worker Launcher Exploitation status Not known exploited Fix YesAffected product A Apache Storm Worker Launcher Published 09/14/2026 Severity High CVE-2026-82430Apache Storm Worker Launcher: Local Privilege Escalation to Root via Container Command Files Chowned to the Tenant Exploitation status Not known exploited Fix YesAffected product A Apache Storm Worker Launcher Published 09/14/2026 Severity High CVE-2026-82431Apache Storm Client: Authorization Bypass When nimbus.groups Is Configured Without nimbus.users Exploitation status Not known exploited Fix YesAffected product A Apache Storm Client Published 09/14/2026 Severity Critical CVE-2026-82433Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Daemon Configuration via Nimbus and the UI Exploitation status Not known exploited Fix YesAffected product A Apache Storm Nimbus Published 09/14/2026 Severity Medium CVE-2026-82432Apache Storm Nimbus: Blobstore Authorization Bypass via Rebalance Configuration Overrides Exploitation status Not known exploited Fix YesAffected product A Apache Storm Nimbus Published 09/14/2026 Severity High CVE-2026-82434Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs Exploitation status Not known exploited Fix YesAffected product A Apache Storm Nimbus Published 09/14/2026 Severity Critical CVE-2026-82435Apache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker Messaging Decoder Exploitation status Not known exploited Fix YesAffected product A Apache Storm Worker Published 09/14/2026 Severity Critical CVE-2026-82437Apache Storm Logviewer: Log Access Controls Not Enforced by Logviewer Exploitation status Not known exploited Fix YesAffected product A Apache Storm Logviewer Published 09/14/2026 Severity Medium CVE-2026-82426Apache Storm Nimbus: Arbitrary File Read on Nimbus via Unvalidated Uploaded Jar Location Exploitation status Not known exploited Fix YesAffected product A Apache Storm Nimbus Published 09/14/2026 Severity Medium CVE-2026-82438Apache Storm Webapp: Authenticated API Responses Exposed to Arbitrary Web Origins Exploitation status Not known exploited Fix YesAffected product A Apache Storm Webapp Published 09/14/2026 Severity High CVE-2026-82439Apache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPC Exploitation status Not known exploited Fix YesAffected product A Apache Storm DRPC Published 09/14/2026 Severity Critical CVE-2026-82441Apache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service via Unvalidated Topology Dependency Keys Exploitation status Not known exploited Fix YesAffected product A Apache Storm Nimbus Published 09/14/2026 Severity Critical CVE-2026-84179Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Merged Daemon Configuration via the Topology Page Exploitation status Not known exploited Fix YesAffected product A Apache Storm Nimbus Published 09/14/2026 Severity Medium CVE-2026-73191Apache Syncope: CAS service URL injection via Forwarded HTTP headers Exploitation status Not known exploited Fix YesAffected product A Apache Syncope Published 09/14/2026 Severity Medium CVE-2026-73195Apache Syncope: CSV export spreadsheet formula injection Exploitation status Not known exploited Fix YesAffected product A Apache Syncope Published 09/14/2026 Severity High CVE-2026-73236Apache Syncope: Cross-Realm authorization bypass in delegated administration Exploitation status Not known exploited Fix YesAffected product A Apache Syncope Published 09/14/2026 Severity High CVE-2026-73370Apache Syncope: Cross-Realm boundaries reconciliation bypass Exploitation status Not known exploited Fix YesAffected product A Apache Syncope Published 09/14/2026 Severity Critical CVE-2026-73178Apache Syncope: JWT Access Token takeover Exploitation status Not known exploited Fix YesAffected product A Apache Syncope Published 09/14/2026 Severity High CVE-2026-73470Apache Syncope: Delegating users can grant unowned Roles Exploitation status Not known exploited Fix YesAffected product A Apache Syncope Published 09/14/2026 Severity Critical CVE-2026-73579Apache Syncope: Non-recursive Any search could skip Realms restrictions Exploitation status Not known exploited Fix YesAffected product A Apache Syncope Published 09/14/2026 Severity Critical CVE-2026-75015Apache Syncope: Nested secrets leak cleartext into audit records readable Exploitation status Not known exploited Fix YesAffected product A Apache Syncope Published 09/14/2026 Severity Medium CVE-2026-75030Apache Syncope: Incomplete authorization checks for Group members deprovisioning Exploitation status Not known exploited Fix YesAffected product A Apache Syncope Published 09/14/2026 Severity Critical CVE-2026-77051Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search Exploitation status Not known exploited Fix YesAffected product A Apache Syncope Published 09/14/2026 Severity Critical CVE-2026-73668Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values Exploitation status Not known exploited Fix YesAffected product A Apache Syncope Published 09/14/2026 Severity Critical CVE-2026-77147Apache Syncope: Groovy Sandbox escape for empty CommandArgs Exploitation status Not known exploited Fix YesAffected product A Apache Syncope Published 09/14/2026 Severity Medium CVE-2026-77181Apache Syncope: ClientApp update entitlement not effective Exploitation status Not known exploited Fix YesAffected product A Apache Syncope Published 09/14/2026 Severity Critical CVE-2026-77883Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist Exploitation status Not known exploited Fix YesAffected product A Apache Syncope Published 09/14/2026 Severity Medium CVE-2026-78318Apache Syncope: Unauthenticated reflected XSS in Console and Enduser Exploitation status Not known exploited Fix YesAffected product A Apache Syncope Published 09/14/2026 Severity Medium CVE-2026-78330Apache Syncope: Privilege escalation for admin user via JWT authentication Exploitation status Not known exploited Fix YesAffected product A Apache Syncope Published 09/14/2026 Severity Critical CVE-2026-78336Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user Exploitation status Not known exploited Fix YesAffected product A Apache Syncope Published 09/14/2026 Severity High CVE-2026-82232Apache Syncope: SQL injection via sort parameter in Task search Exploitation status Not known exploited Fix YesAffected product A Apache Syncope Published 09/14/2026 Severity Critical CVE-2026-86460Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence Exploitation status Not known exploited Fix YesAffected product A Apache Syncope Published 09/14/2026 Severity Critical