CVE Tools

Apache-software-foundation

2,485 CVEs tracked since 2006. Since Sep 2021, 20 of them reached CISA KEV.

Apache-software-foundation CVEs per month

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Apache-software-foundation CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-09221
2021-10172
2021-11250
2021-12173
2022-01320
2022-02141
2022-03120
2022-04131
2022-05100
2022-06180
2022-07131
2022-08260
2022-09300
2022-10200
2022-11280
2022-12210
2023-01250
2023-02160
2023-03null or fewer
2023-04211
2023-05311
2023-06180
2023-07290
2023-08170
2023-09170
2023-10262
2023-11280
2023-12240
2024-01150
2024-02380
2024-03290
2024-04271
2024-0581
2024-06120
2024-07461
2024-08181
2024-09141
2024-10150
2024-11250
2024-12170
2025-01160
2025-02150
2025-03231
2025-04190
2025-05150
2025-06210
2025-07240
2025-08210
2025-09120
2025-10200
2025-11190
2025-12220
2026-01220
2026-02250
2026-03200
2026-04861
2026-05870
2026-061210
2026-071810
2026-081670
2026-09930

Products

The products that kept showing up in Apache-software-foundation's monthly top three, with their CVEs summed over those months.

  1. Apache Airflow9315 months
  2. Apache HTTP Server7411 months
  3. Apache Traffic Server637 months
  4. HTTP Server589 months
  5. Apache Superset448 months
  6. Apache Cloudstack346 months
  7. Apache Ofbiz295 months
  8. Airflow277 months
  9. Apache Inlong256 months
  10. Apache Thrift232 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Apache-software-foundation.

  1. CVE-2026-92550Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder7.5
  2. CVE-2026-92560Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder7.5
  3. CVE-2026-92573Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering6.5
  4. CVE-2026-92564Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing—
  5. CVE-2026-92608Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-107.5
  6. CVE-2026-92609Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication9.8
  7. CVE-2026-97636Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled key6.5
  8. CVE-2026-57590Apache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unauthorized Cross-Project Operations8.1
  9. CVE-2026-86247Apache Tomcat Native: Client certificate requirements can be down-graded7.4
  10. CVE-2026-86246Apache Tomcat Native: Insecure OpenSSL options enabled9.1
  11. CVE-2026-86243Apache Tomcat Native: DoS via TLS handshake7.5
  12. CVE-2026-87022Apache Tomcat: WebSocket message smuggling with per-message-deflate7.5
  13. CVE-2026-86350Apache Tomcat: Regression in fix for CVE-2026-41293 can trigger request header mix-up9.1
  14. CVE-2026-86248Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled9.8
  15. CVE-2026-79677Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout7.5

The record

Peak rank
#5 in Jul 2026
Busiest month shown
Jul 2026, 181 CVEs
Months with a KEV entry
16 since Sep 2021
Monthly snapshots
140 since 2006
Apache-software-foundation's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store