#apachefoundation
CVE-2026-76183 - apache tomcat
Apache Tomcat versions up to 11.0.25, 10.1.59, and 9.0.121 let users bypass security checks on WebSocket connections, potentially letting anyone…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachetomcat #apachefoundation #Debian13 #CVE #infosec
CVE-2026-76183: Apache Tomcat allows unauthorized WebSocket access
Apache Tomcat versions up to 11.0.25, 10.1.59, and 9.0.121 let users bypass security checks on WebSocket connections, potentially letting anyone interact.
stackflag.com
September 23, 2026 at 11:00 PM
CVE-2026-86350 - apache tomcat
Versions of Apache Tomcat 9.0.118‑9.0.121, 10.1.55‑10.1.59, and 11.0.22‑11.0.25 can misinterpret incoming HTTP/2 traffic, causing request headers to…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachetomcat #apachefoundation #Debian13 #CVE #infosec
CVE-2026-86350: Apache Tomcat may mix up web requests
Versions of Apache Tomcat 9.0.118‑9.0.121, 10.1.55‑10.1.59, and 11.0.22‑11.0.25 can misinterpret incoming HTTP/2 traffic, causing request headers to.
stackflag.com
September 23, 2026 at 11:20 PM
CVE-2026-86248 - apache tomcat
Certain versions of Apache Tomcat (11.0.0-M14 to 11.0.25, 10.1.22 to 10.1.59, and 9.0.92 to 9.0.121) can incorrectly allow client certificate…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachetomcat #apachefoundation #Debian13 #CVE #infosec
CVE-2026-86248: Apache Tomcat may accept invalid client certificates
Certain versions of Apache Tomcat (11.0.0-M14 to 11.0.25, 10.1.22 to 10.1.59, and 9.0.92 to 9.0.121) can incorrectly allow client certificate.
stackflag.com
September 23, 2026 at 11:10 PM
CVE-2026-92609 - apache qpid broker-j
When a user logs into the management interface of Apache Qpid Broker-J, the system keeps the same session identifier instead of creating a new one. This allows a remote…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachefoundation #CVE #infosec
CVE-2026-92609: Apache Qpid Broker-J reuses session ID after login
When a user logs into the management interface of Apache Qpid Broker-J, the system keeps the same session identifier instead of creating a new one.
stackflag.com
September 25, 2026 at 2:30 PM
CVE-2026-82331 - apache buildstream
The tar handling part of Apache BuildStream may follow symbolic links inside a malicious source archive and create or overwrite files on the…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachebuildstream #apachefoundation #Debian12 #CVE #infosec
CVE-2026-82331: Apache BuildStream tar plugin can write files via crafted archive
The tar handling part of Apache BuildStream may follow symbolic links inside a malicious source archive and create or overwrite files on the system with.
stackflag.com
September 23, 2026 at 11:00 PM
CVE-2026-86473 - apache airflow
When users sign out of Apache Airflow using a bearer token in the Authorization header, the system only clears the browser cookie and leaves the token active…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apacheairflow #apachefoundation #CVE #infosec
CVE-2026-86473: Apache Airflow logout does not revoke bearer token
When users sign out of Apache Airflow using a bearer token in the Authorization header, the system only clears the browser cookie and leaves the token.
stackflag.com
September 21, 2026 at 7:20 PM
CVE-2026-94301 - apache mina
Versions 2.0.30, 2.0.29, 2.1.14 and 2.1.13 of Apache MINA do not include a fix that blocks a way to bypass security checks using Java proxy objects. This means an…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachemina #apachefoundation #CVE #infosec
CVE-2026-94301: Apache MINA 2.0/2.1 allows filter bypass
Versions 2.0.30, 2.0.29, 2.1.14 and 2.1.13 of Apache MINA do not include a fix that blocks a way to bypass security checks using Java proxy objects.
stackflag.com
September 21, 2026 at 3:00 PM
CVE-2026-49364 - apache artemis
If an attacker can see traffic on the same network, they can trick Artemis into sending its cluster administrator credentials during the initial connection…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apacheartemis #apachefoundation #CVE #infosec
CVE-2026-49364: Apache Artemis may expose admin passwords during cluster setup
If an attacker can see traffic on the same network, they can trick Artemis into sending its cluster administrator credentials during the initial.
stackflag.com
September 10, 2026 at 4:50 PM
CVE-2026-32227 - apache ranger
Apache Ranger's lookup feature can be exploited to inject malicious SQL code. This can lead to unauthorized data access or modification. To fix this issue,…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apacheranger #apachefoundation #CVE #infosec
CVE-2026-32227: Apache Ranger: SQL Injection in Lookup Functionality
Apache Ranger's lookup feature can be exploited to inject malicious SQL code. This can lead to unauthorized data access or modification.
stackflag.com
August 12, 2026 at 4:40 PM
CVE-2026-82617 - apache opennlp
OpenNLP’s built‑in email and web‑address detectors can be tricked by specially crafted text, causing the program to use excessive CPU time or run out of memory…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apacheopennlp #apachefoundation #CVE #infosec
CVE-2026-82617: Apache OpenNLP may hang or crash on malicious text
OpenNLP’s built‑in email and web‑address detectors can be tricked by specially crafted text, causing the program to use excessive CPU time or run out of.
stackflag.com
September 11, 2026 at 6:40 PM
CVE-2026-68536 - apache myfaces
Certain versions of Apache MyFaces can be told to access internal network locations or read files on the server, which could expose sensitive information. This…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachemyfaces #apachefoundation #CVE #infosec
CVE-2026-68536: Apache MyFaces may load internal resources without permission
Certain versions of Apache MyFaces can be told to access internal network locations or read files on the server, which could expose sensitive information.
stackflag.com
September 17, 2026 at 8:40 PM
CVE-2026-76187 - apache airflow keycloak provider
If your Airflow installation uses the Keycloak authentication manager and shares the Keycloak realm with other applications, any of those applications can…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachefoundation #CVE #infosec
CVE-2026-76187: Apache Airflow Keycloak provider lets other apps log in
If your Airflow installation uses the Keycloak authentication manager and shares the Keycloak realm with other applications, any of those applications can.
stackflag.com
September 17, 2026 at 8:40 PM
CVE-2026-41041 - apache gravitino
Apache Gravitino's MCP REST client fails to properly encode user input in URLs, potentially allowing attackers to access sensitive data or API endpoints.…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachegravitino #apachefoundation #CVE #infosec
CVE-2026-41041: Apache Gravitino: Malicious URLs Can Access Sensitive API Data
Apache Gravitino's MCP REST client fails to properly encode user input in URLs, potentially allowing attackers to access sensitive data or API endpoints.
stackflag.com
July 13, 2026 at 5:40 PM
CVE-2026-82311 - apache airflow fab provider
When a password is changed in Airflow using the FAB authentication manager with database‑backed sessions, existing user sessions are not removed because the…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachefoundation #CVE #infosec
CVE-2026-82311: Apache Airflow FAB provider password reset leaves sessions active
When a password is changed in Airflow using the FAB authentication manager with database‑backed sessions, existing user sessions are not removed because.
stackflag.com
September 17, 2026 at 8:20 PM
CVE-2026-86462 - apache airflow fab provider
When a password is changed through the admin interface in Apache Airflow's FAB provider, any existing login sessions that use the database for session storage…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachefoundation #CVE #infosec
CVE-2026-86462: Apache Airflow FAB provider password change leaves old sessions active
When a password is changed through the admin interface in Apache Airflow's FAB provider, any existing login sessions that use the database for session.
stackflag.com
September 17, 2026 at 8:20 PM
CVE-2026-76186 - apache airflow keycloak provider
If you run Apache Airflow version 3.3 or newer with the Keycloak authentication add‑on, a user’s login session can be combined with a different person’s…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachefoundation #CVE #infosec
CVE-2026-76186: Apache Airflow Keycloak provider can let user assume another's rights
If you run Apache Airflow version 3.3 or newer with the Keycloak authentication add‑on, a user’s login session can be combined with a different person’s.
stackflag.com
September 17, 2026 at 8:30 PM
CVE-2026-82431 - apache storm client
If the Storm configuration defines only group restrictions (nimbus.groups) and leaves the user list (nimbus.users) empty, the system does not enforce those group rules.…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachefoundation #CVE #infosec
CVE-2026-82431: Apache Storm client allows any user to submit jobs
If the Storm configuration defines only group restrictions (nimbus.groups) and leaves the user list (nimbus.users) empty, the system does not enforce.
stackflag.com
September 14, 2026 at 9:30 PM
CVE-2026-77051 - apache syncope
In certain versions of Apache Syncope, an admin with proper rights can insert malicious input that makes the system execute any database command. This could let…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-77051: Apache Syncope lets admin run unauthorized database commands
In certain versions of Apache Syncope, an admin with proper rights can insert malicious input that makes the system execute any database command.
stackflag.com
September 14, 2026 at 9:10 PM
CVE-2026-87802 - apache syncope
Apache Syncope versions from 3.0.0‑M0 to 4.1.2 can accept forged authentication tokens when OAuth 2.0 is set up without a proper key source. An attacker could…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-87802: Apache Syncope OAuth mis-checks signatures, allowing impersonation
Apache Syncope versions from 3.0.0‑M0 to 4.1.2 can accept forged authentication tokens when OAuth 2.0 is set up without a proper key source.
stackflag.com
September 14, 2026 at 8:30 PM
CVE-2026-82435 - apache storm worker
Apache Storm worker nodes accept specially crafted network packets before checking who sent them. An attacker who can reach a worker's port could cause the worker to use…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachefoundation #CVE #infosec
CVE-2026-82435: Apache Storm Worker can be crashed by unauthenticated network traffic
Apache Storm worker nodes accept specially crafted network packets before checking who sent them.
stackflag.com
September 14, 2026 at 9:30 PM
CVE-2026-82232 - apache syncope
If an administrator with sufficient rights uses the task‑search feature, they can insert specially crafted sorting instructions that cause the system to execute…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-82232: Apache Syncope allows admins to run unauthorized database commands
If an administrator with sufficient rights uses the task‑search feature, they can insert specially crafted sorting instructions that cause the system to.
stackflag.com
September 14, 2026 at 8:40 PM
CVE-2026-87785 - apache syncope
Certain versions of Apache Syncope (3.0.0‑M0 through 3.0.16 and 4.0.0‑M0 through 4.1.2) can expose the settings used to verify internal login tokens. If an…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-87785: Apache Syncope allows attackers to impersonate users
Certain versions of Apache Syncope (3.0.0‑M0 through 3.0.16 and 4.0.0‑M0 through 4.1.2) can expose the settings used to verify internal login tokens.
stackflag.com
September 14, 2026 at 8:30 PM
CVE-2026-82439 - apache storm drpc
The DRPC component of Apache Storm stores each request name forever, even if it is never used again. An attacker can send many fake request names and cause the server to…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachefoundation #CVE #infosec
CVE-2026-82439: Apache Storm DRPC can run out of memory
The DRPC component of Apache Storm stores each request name forever, even if it is never used again.
stackflag.com
September 14, 2026 at 9:20 PM
CVE-2026-73579 - apache syncope
Apache Syncope versions up to 3.0.16, 4.0.7 and 4.1.2 can omit permission checks on certain search queries, allowing users to see information they shouldn’t.…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-73579: Apache Syncope may expose data to unauthorized users
Apache Syncope versions up to 3.0.16, 4.0.7 and 4.1.2 can omit permission checks on certain search queries, allowing users to see information they shouldn’t.
stackflag.com
September 14, 2026 at 8:50 PM
CVE-2026-73668 - apache syncope
In certain versions of Apache Syncope, an administrator who has rights in one area could use the REST interface to see the full configuration of connectors…

Too many irrelevant or confusing CVEs? Use stackflag.com

#apachesyncope #apachefoundation #CVE #infosec
CVE-2026-73668: Apache Syncope admin can view other realm connector settings
In certain versions of Apache Syncope, an administrator who has rights in one area could use the REST interface to see the full configuration of.
stackflag.com
September 14, 2026 at 9:00 PM