apache

28 records · 0 with a public proof-of-concept

Disclosed vulnerabilities where the NVD names apache as an affected vendor, highest CVSS first.

  1. CRITICAL 9.8CVE-2026-61486

    ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an al

    lucy

    AI risk analysis on Exploit-DB.ai →

  2. CRITICAL 9.8CVE-2026-61484

    ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find

    lucy

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.5CVE-2026-61485

    ** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommend

    lucy

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.5CVE-2026-61483

    ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alterna

    lucy

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.5CVE-2026-68073

    A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the iss

    qpid broker-j

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 7.5CVE-2026-67592

    It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are

    qpid protonj2

    AI risk analysis on Exploit-DB.ai →

  7. HIGH 7.5CVE-2026-67590

    A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue

    qpid protonj2

    AI risk analysis on Exploit-DB.ai →

  8. HIGH 7.5CVE-2026-67552

    A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the i

    qpid proton-dotnet

    AI risk analysis on Exploit-DB.ai →

  9. HIGH 7.5CVE-2026-66274

    A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the iss

    qpid proton-j

    AI risk analysis on Exploit-DB.ai →

  10. HIGH 7.5CVE-2026-68074

    A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes th

    qpid broker-j

    AI risk analysis on Exploit-DB.ai →

  11. HIGH 7.5CVE-2026-68060

    A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fix

    qpid broker-j

    AI risk analysis on Exploit-DB.ai →

  12. HIGH 7.5CVE-2026-67589

    A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes

    qpid protonj2

    AI risk analysis on Exploit-DB.ai →

  13. HIGH 7.5CVE-2026-67588

    A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the

    qpid protonj2

    AI risk analysis on Exploit-DB.ai →

  14. HIGH 7.5CVE-2026-67551

    pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fi

    qpid proton-dotnet

    AI risk analysis on Exploit-DB.ai →

  15. HIGH 7.5CVE-2026-67465

    A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes

    qpid proton-dotnet

    AI risk analysis on Exploit-DB.ai →

  16. HIGH 7.5CVE-2026-66273

    A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fix

    qpid proton-j

    AI risk analysis on Exploit-DB.ai →

  17. HIGH 7.5CVE-2026-66257

    A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes th

    qpid proton-j

    AI risk analysis on Exploit-DB.ai →

  18. MEDIUM 6.5CVE-2026-68080

    It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are

    qpid broker-j

    AI risk analysis on Exploit-DB.ai →

  19. MEDIUM 6.5CVE-2026-68078

    It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users ar

    qpid broker-j

    AI risk analysis on Exploit-DB.ai →

  20. MEDIUM 6.5CVE-2026-68077

    An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgr

    qpid broker-j

    AI risk analysis on Exploit-DB.ai →

  21. MEDIUM 6.5CVE-2026-68075

    An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.

    qpid broker-j

    AI risk analysis on Exploit-DB.ai →

  22. MEDIUM 6.5CVE-2026-67591

    An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.

    qpid protonj2

    AI risk analysis on Exploit-DB.ai →

  23. MEDIUM 6.5CVE-2026-67555

    It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users

    qpid proton-dotnet

    AI risk analysis on Exploit-DB.ai →

  24. MEDIUM 6.5CVE-2026-67554

    An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to

    qpid proton-dotnet

    AI risk analysis on Exploit-DB.ai →

  25. MEDIUM 6.5CVE-2026-67553

    An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.

    qpid proton-dotnet

    AI risk analysis on Exploit-DB.ai →

  26. MEDIUM 6.5CVE-2026-66277

    It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users ar

    qpid proton-j

    AI risk analysis on Exploit-DB.ai →

  27. MEDIUM 6.5CVE-2026-66276

    An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgr

    qpid proton-j

    AI risk analysis on Exploit-DB.ai →

  28. MEDIUM 6.5CVE-2026-66275

    An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.

    qpid proton-j

    AI risk analysis on Exploit-DB.ai →