Apache-software-foundation
2,485 CVEs tracked since 2006. Since Sep 2021, 20 of them reached CISA KEV.
Apache-software-foundation CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-09 | 22 | 1 |
| 2021-10 | 17 | 2 |
| 2021-11 | 25 | 0 |
| 2021-12 | 17 | 3 |
| 2022-01 | 32 | 0 |
| 2022-02 | 14 | 1 |
| 2022-03 | 12 | 0 |
| 2022-04 | 13 | 1 |
| 2022-05 | 10 | 0 |
| 2022-06 | 18 | 0 |
| 2022-07 | 13 | 1 |
| 2022-08 | 26 | 0 |
| 2022-09 | 30 | 0 |
| 2022-10 | 20 | 0 |
| 2022-11 | 28 | 0 |
| 2022-12 | 21 | 0 |
| 2023-01 | 25 | 0 |
| 2023-02 | 16 | 0 |
| 2023-03 | null or fewer | |
| 2023-04 | 21 | 1 |
| 2023-05 | 31 | 1 |
| 2023-06 | 18 | 0 |
| 2023-07 | 29 | 0 |
| 2023-08 | 17 | 0 |
| 2023-09 | 17 | 0 |
| 2023-10 | 26 | 2 |
| 2023-11 | 28 | 0 |
| 2023-12 | 24 | 0 |
| 2024-01 | 15 | 0 |
| 2024-02 | 38 | 0 |
| 2024-03 | 29 | 0 |
| 2024-04 | 27 | 1 |
| 2024-05 | 8 | 1 |
| 2024-06 | 12 | 0 |
| 2024-07 | 46 | 1 |
| 2024-08 | 18 | 1 |
| 2024-09 | 14 | 1 |
| 2024-10 | 15 | 0 |
| 2024-11 | 25 | 0 |
| 2024-12 | 17 | 0 |
| 2025-01 | 16 | 0 |
| 2025-02 | 15 | 0 |
| 2025-03 | 23 | 1 |
| 2025-04 | 19 | 0 |
| 2025-05 | 15 | 0 |
| 2025-06 | 21 | 0 |
| 2025-07 | 24 | 0 |
| 2025-08 | 21 | 0 |
| 2025-09 | 12 | 0 |
| 2025-10 | 20 | 0 |
| 2025-11 | 19 | 0 |
| 2025-12 | 22 | 0 |
| 2026-01 | 22 | 0 |
| 2026-02 | 25 | 0 |
| 2026-03 | 20 | 0 |
| 2026-04 | 86 | 1 |
| 2026-05 | 87 | 0 |
| 2026-06 | 121 | 0 |
| 2026-07 | 181 | 0 |
| 2026-08 | 167 | 0 |
| 2026-09 | 93 | 0 |
Products
The products that kept showing up in Apache-software-foundation's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Apache-software-foundation.
- CVE-2026-92550Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder7.5
- CVE-2026-92560Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder7.5
- CVE-2026-92573Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering6.5
- CVE-2026-92564Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing—
- CVE-2026-92608Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-107.5
- CVE-2026-92609Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication9.8
- CVE-2026-97636Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled key6.5
- CVE-2026-57590Apache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unauthorized Cross-Project Operations8.1
- CVE-2026-86247Apache Tomcat Native: Client certificate requirements can be down-graded7.4
- CVE-2026-86246Apache Tomcat Native: Insecure OpenSSL options enabled9.1
- CVE-2026-86243Apache Tomcat Native: DoS via TLS handshake7.5
- CVE-2026-87022Apache Tomcat: WebSocket message smuggling with per-message-deflate7.5
- CVE-2026-86350Apache Tomcat: Regression in fix for CVE-2026-41293 can trigger request header mix-up9.1
- CVE-2026-86248Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled9.8
- CVE-2026-79677Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout7.5
The record
- Peak rank
- #5 in Jul 2026
- Busiest month shown
- Jul 2026, 181 CVEs
- Months with a KEV entry
- 16 since Sep 2021
- Monthly snapshots
- 140 since 2006