imPC@ndo IT

Apache vulnerabilities

3290 CVE

CVE-2026-71290
Critical 9.1

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between th…

apache httpclient
0.00EPSS
CVE-2026-69223
Critical 9.1

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.

apache allura
0.00EPSS
CVE-2026-68872
Medium 6.5

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mo…

apache apache-airflow-providers-amazon
0.00EPSS
CVE-2026-68871
Medium 6.5

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in …

apache apache-airflow-providers-apache-yandex
0.00EPSS
CVE-2026-65948
High 7.3

UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommended option for production deployments.  Users are recommended to upgrade to version 2.9.0, which fixes this issue.

apache ranger
0.00EPSS
CVE-2026-65945
Medium 6.5

Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

apache ranger
0.00EPSS
CVE-2026-65942
High 7.5

TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

apache ranger
0.00EPSS
CVE-2026-55814
High 7.5

Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

apache ranger
0.00EPSS
CVE-2026-55799
Critical 9.8

Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

apache ranger
0.00EPSS
CVE-2026-44416
Critical 9.8

Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

apache ranger
0.00EPSS
CVE-2026-42537
Critical 9.8

Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

apache ranger
0.00EPSS
CVE-2026-40920
Critical 9.8

Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

apache ranger
0.00EPSS
CVE-2026-32227
Critical 9.8

SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the issue.

apache ranger
0.00EPSS
CVE-2026-28672
Critical 9.8

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8.

apache ranger
0.00EPSS
CVE-2026-35554
High 8.7

A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. When a produce batch expires due to delivery.timeout.ms while a network request containing that batch is still …

apache kafka
0.00EPSS