announce
Thread
Date
Earlier messages
Messages by Thread
[ANNOUNCE] Apache Qpid protonj2 1.3.0 released
Timothy Bish
[ANNOUNCEMENT] HttpComponents Client 5.7-alpha1 Released
Oleg Kalnichevski
[ANNOUNCE] Apache Camel 4.18.4 (LTS) Released
Gregor Zurowski
[ANNOUNCE] Apache Fory 1.6.1 released
Shawn Yang
[ANNOUNCE] Apache Ratis 3.3.0 Release
Xinyu Tan
[ANNOUNCE] Apache Camel 4.14.9 (LTS) Released
Gregor Zurowski
[ANNOUNCE] Apache Texera 1.2.0-incubating released
Xuan Gu
[ANNOUNCE] Apache Groovy 6.0.0-beta-2 Released
Paul King
[ANNOUNCE] Apache Groovy 5.1.0 Released
Paul King
[ANN] CVE-2026-73633: Apache Struts: Unbounded read of a JSON request body - S2-072
Lukasz Lenart
[ANNOUNCE] Apache Pulsar C# Client DotPulsar 5.3.2 released
David Jensen
[ANN] CVE-2026-73634: Apache Struts: Unbounded read of a Content Security Policy violation report - S2-073
Lukasz Lenart
[ANN] CVE-2026-73635: Apache Struts: Unbounded growth of localized-text caches driven by the request locale - S2-074
Lukasz Lenart
[ANN] CVE-2026-73631: Apache Struts: Shared parsing state in the JSON plugin - S2-070
Lukasz Lenart
[ANN] CVE-2026-73632: Apache Struts: Shared serialization state in the JSON plugin - S2-071
Lukasz Lenart
[ANNOUNCE] Apache Bigtop 3.6.0 released
Masatake Iwasaki
CVE-2026-66256: Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API)
Arnout Engelen
CVE-2026-71290: Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)
Oleg Kalnichevski
CVE-2026-64607: Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
Oleg Kalnichevski
CVE-2026-73240: Apache Allura: Git command injection
Dave Brondsema
CVE-2026-73237: Apache Allura: XSS in markdown pipeline
Dave Brondsema
CVE-2026-73239: Apache Allura: Missing permission checks IDOR
Dave Brondsema
CVE-2026-73238: Apache Allura: XSS in code display
Dave Brondsema
[ANNOUNCE] Apache Arrow 25.0.1 released
Raúl Cumplido
[ANNOUNCE] Apache Lucene 10.5.1 released
Ignacio Vera
Fwd: [ANNOUNCE] Apache Commons Collections 4.6.0
Gary Gregory
CVE-2026-58076: Apache Airflow: Unguarded import_string() of airflow_exc_ser / base_exc_ser exception nodes in BaseSerialization.deserialize enables DAG-author RCE on Scheduler / API Server
Rahul Vats
CVE-2026-68970: Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UI
Rahul Vats
CVE-2026-67260: Apache Airflow: DAG-author remote code execution on the Scheduler via awaiting_input next_kwargs deserialization
Rahul Vats
CVE-2026-68969: Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartext
Rahul Vats
CVE-2026-68076: Apache Airflow: Connections test API: team-scope guard bypass resolves another team's environment Connection
Rahul Vats
CVE-2026-68971: Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run result endpoints
Rahul Vats
CVE-2026-68968: Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretations of the backfill id
Rahul Vats
CVE-2026-65017: Apache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi-team masking bypass)
Rahul Vats
CVE-2026-67587: Apache Airflow: DAG-author remote code execution on the Scheduler via a Serde `Callback` deserialization gadget
Rahul Vats
CVE-2026-54183: Apache Airflow: Airflow Variables were not masked in the UI for authenticated users
Rahul Vats
CVE-2026-59242: Apache Airflow: Arbitrary airflow.* class instantiation on the API server via the XCom deserialize endpoint
Rahul Vats
CVE-2026-59244: Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI
Rahul Vats
[ANNOUNCE] Apache Airflow 3.3.1 Released
Rahul Vats
CVE-2026-68868: Apache Airflow Google provider: google Secret Manager backend: team scope is never applied, exposing every team's Connections and Variables
Jarek Potiuk
[ANNOUNCE] Apache Qpid JMS 1.17.0 released
Robbie Gemmell
[ANNOUNCE] Apache Qpid JMS 2.11.0 released
Robbie Gemmell
CVE-2026-69223: Apache Allura: Server-side request forgery
Dave Brondsema
[ANN] Apache Struts 7.3.0
Lukasz Lenart
[ANN] Apache Struts 6.11.0
Lukasz Lenart
Fwd: [ANNOUNCE] Apache Airflow Providers prepared on 2026-08-08 are released
Jarek Potiuk
CVE-2026-68872: Apache Airflow Amazon provider: amazon SSM / Secrets Manager backends: team-scope guard bypass resolves another team's Connection or Variable
Jarek Potiuk
CVE-2026-68870: Apache Airflow Microsoft Azure provider: microsoft.azure Key Vault backend: team-scope guard bypass resolves another team's Connection or Variable
Jarek Potiuk
CVE-2026-68871: Apache Airflow Yandex provider: yandex Lockbox backend: team-scope guard bypass resolves another team's Connection or Variable
Jarek Potiuk
[ANNOUNCE] Apache ActiveMQ 6.3.1 has been released!
Christopher Shannon
[ANNOUNCE] Apache ActiveMQ 5.19.10 has been released!
Christopher Shannon
[ANNOUNCE] Apache ActiveMQ 6.2.9 has been released!
Christopher Shannon
[ANNOUNCEMENT] HttpComponents Client 5.6.4 Released
Oleg Kalnichevski
CVE-2026-44630: Apache IoTDB: RPC service denial of service via unchecked Thrift string length
Haonan Hou
CVE-2026-65948: Apache Ranger: UnixAuth lacks brute-force protection
Velmurugan Periasamy
CVE-2026-55814: Apache Ranger: Download APIs expose plugin data without authentication
Velmurugan Periasamy
CVE-2026-65945: Apache Ranger: Logs contain replayable JWT bearer tokens
Velmurugan Periasamy
CVE-2026-65942: Apache Ranger: Clients accept TLS certificates issued for other hostnames
Velmurugan Periasamy
CVE-2026-55799: Apache Ranger: Remote Code Execution Vulnerability in GraalScriptEngineCreator
Velmurugan Periasamy
CVE-2026-44416: Apache Ranger: Remote Code Execution via Arbitrary Class Instantiation
Velmurugan Periasamy
CVE-2026-42537: Apache Ranger: Remote Code Execution via JDBC URL Injection
Velmurugan Periasamy
CVE-2026-40920: Apache Ranger: Privilege Escalation via URL Parameter
Velmurugan Periasamy
CVE-2026-32227: Apache Ranger: SQL Injection vulnerability in lookup functionality
Velmurugan Periasamy
CVE-2026-28672: Apache Ranger: OS Command Injection via Username in UnixUserGroupBuilder
Velmurugan Periasamy
[ANNOUNCE] Apache Airflow Providers prepared on 2026-08-06 are released
Jarek Potiuk
[ANNOUNCE] Apache Ranger 2.9.0 released
Madhan Neethiraj
CVE-2026-61899: Apache Tapestry: Possible classpath file download through URL manipulation
Thiago Henrique De Paula Figueiredo
[ANNOUNCE] Apache Qpid proton-dotnet 1.1.0 released
Timothy Bish
[ANNOUNCE] Apache Fory 1.6.0 released
Shawn Yang
CVE-2026-71559: Apache Fory: Uncaught panic (remote DoS) in Go meta-string decoder from untrusted metadata
Chaokun Yang
CVE-2026-71558: Apache Fory: Heap type confusion in C++ polymorphic smart-pointer deserialization
Chaokun Yang
CVE-2026-71560: Apache Fory: Out-of-bounds heap read in C++ struct deserializer tagged-int fast-path
Chaokun Yang
[ANNOUNCE] Apache Paimon 2.0.0 released
Jingsong Lee
[ANNOUNCEMENT] Apache SkyWalking Go 0.7.0 Released
han liu
[ANN] Maven Resolver Ant Tasks 2.0.0 released
Tamás Cservenák
[ANNOUNCE] Apache Jackrabbit 2.22.4 released
Julian Reschke
[ANNOUNCE] Apache Grails 7.0.15
James Fredley
[ANNOUNCE] Apache Grails 8.0.0-M5
James Fredley
[ANNOUNCE] Apache Grails 7.1.5
James Fredley
[ANNOUNCE] Apache Grails 7.2.2
James Fredley
CVE-2026-34191: Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
Eric Covener
CVE-2026-34502: Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client
Eric Covener
CVE-2026-34501: Apache Portable Runtime Utility: Heap buffer overflow in APR redis client
Eric Covener
CVE-2026-32327: Apache Portable Runtime Utility: apr-util XML stack recursion crash
Eric Covener
CVE-2025-49506: Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
Eric Covener
[ANNOUNCEMENT] Apache Portable Runtime Utility 1.6.4 Released
covener
CVE-2026-68481: Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider
Colm O hEigeartaigh
CVE-2026-68079: Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay
Colm O hEigeartaigh
CVE-2026-65583: Apache CXF: Self-issued ID token claims validation skipped
Colm O hEigeartaigh
CVE-2026-63687: Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters
Colm O hEigeartaigh
CVE-2026-61466: Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation
Colm O hEigeartaigh
CVE-2026-57818: Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider
Colm O hEigeartaigh
CVE-2026-57817: Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow
Colm O hEigeartaigh
CVE-2026-66909: Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage
Colm O hEigeartaigh
CVE-2026-65432: Apache CXF: XXE via WSDL/XSD import parsing
Colm O hEigeartaigh
CVE-2026-64958: Apache CXF: Denial of service via message header attachments
Colm O hEigeartaigh
CVE-2026-57819: Apache CXF: No default restriction on the amount of form parameters per message
Colm O hEigeartaigh
CVE-2026-54225: Apache CXF: Denial of Service attack via large attachments
Colm O hEigeartaigh
CVE-2026-64640: Apache Polaris: register endpoint reads attacker-controlled storage location before allowed-locations validation
Alexandre Dutra
[ANNOUNCE] Apache HBase 3.0.0 is now available for download
Duo Zhang
CVE-2026-60053: Apache Answer: Residual Administrative API Key Access After Role or Account Revocation
Enxin Xie
CVE-2026-48912: Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL
Enxin Xie
CVE-2026-60023: Apache Answer: Unauthorized disclosure of deleted or pending answer content
Enxin Xie
CVE-2026-50749: Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions
Enxin Xie
CVE-2026-48911: Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow
Enxin Xie
CVE-2026-48834: Apache Answer: Denial of service via crafted Accept-Language header parsing
Enxin Xie
[ANNOUNCE] Apache Sedona 1.9.1 released
Jia Yu
CVE-2026-61486: Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input
Piotr Karwasz
CVE-2026-61485: Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index
Piotr Karwasz
CVE-2026-61484: Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS
Piotr Karwasz
CVE-2026-61483: Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow DoS
Piotr Karwasz
[ANNOUNCE] Apache BVal 3.1.0
Markus Jung
[ANNOUNCE] Apache Qpid protonj2 1.2.0 released
Timothy Bish
CVE-2026-67592: Apache Qpid ProtonJ2: Unable to govern the maximum number of transfer frames per incoming delivery
Timothy A. Bish
CVE-2026-67591: Apache Qpid ProtonJ2: Incoming session flow control window can be exceeded
Timothy A. Bish
CVE-2026-67590: Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflow
Timothy A. Bish
CVE-2026-67589: Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-authentication
Timothy A. Bish
CVE-2026-67588: Apache Qpid ProtonJ2: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Timothy A. Bish
CVE-2026-67553: Apache Qpid Proton Dotnet: Incoming session flow control window can be exceeded
Timothy A. Bish
CVE-2026-67555: Apache Qpid Proton Dotnet: Unable to govern the maximum number of transfer frames per incoming delivery
Timothy A. Bish
CVE-2026-67554: Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of service
Timothy A. Bish
CVE-2026-67552: Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stackoverflow
Timothy A. Bish
CVE-2026-67551: Apache Qpid Proton Dotnet: Type size/count handling can lead to excessive allocation pre-authentication
Timothy A. Bish
CVE-2026-67465: Apache Qpid Proton Dotnet: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Timothy A. Bish
CVE-2026-68080: Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service
Daniil Kirilyuk
CVE-2026-68078: Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery
Daniil Kirilyuk
CVE-2026-68075: Apache Qpid Broker-J: Incoming session flow control window can be exceeded
Daniil Kirilyuk
CVE-2026-68077: Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service
Daniil Kirilyuk
CVE-2026-68074: Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Daniil Kirilyuk
CVE-2026-68073: Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow
Daniil Kirilyuk
CVE-2026-68060: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication
Daniil Kirilyuk
[ANNOUNCE] Apache Qpid Proton-J 0.35.0 released
Robbie Gemmell
CVE-2026-66276: Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service
Robbie Gemmell
CVE-2026-66277: Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming delivery
Robbie Gemmell
CVE-2026-66275: Apache Qpid Proton-J: Incoming session flow control window can be exceeded
Robbie Gemmell
CVE-2026-66274: Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow
Robbie Gemmell
CVE-2026-66273: Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authentication
Robbie Gemmell
CVE-2026-66257: Apache Qpid Proton-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Robbie Gemmell
Apache Petri is now retired
Niall Pemberton
Apache ServiceMix is now retired
Niall Pemberton
[ANNOUNCE] Apache Groovy 6.0.0-beta-1 Released
Paul King
Fwd: [ANN] Apache Maven 4.0.0-rc-6 Released
Guillaume Nodet
CVE-2026-68981: Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests
David Handermann
CVE-2026-68980: Apache NiFi: Authorization Bypass for Parameter Context Asset Deletion
David Handermann
CVE-2026-62354: Apache NiFi: Incorrect Authorization for Parameter Context Validation Requests
David Handermann
CVE-2026-68979: Apache NiFi: Missing Authorization for Components Referenced by Parameter Context Updates
David Handermann
[ANNOUNCE] Apache Pulsar 4.2.4 released
Lari Hotari
[ANNOUNCE] Apache Pulsar 4.0.13 released
Lari Hotari
CVE-2026-61372: Apache Jena Fuseki: Web requests using SPARQL Update can escape file restrictions
Andy Seaborne
[ANNOUNCE] Apache NiFi 2.11.0 Released
Pierre Villard
[ANNOUNCE] Apache Polaris 1.7.0
Jean-Baptiste Onofré
Re: [ANNOUNCE] Apache Polaris 1.7.0
Alexandre Dutra
[ANNOUNCE] Apache StormCrawler 3.7.0 released
Davide Polato
[ANN] Apache Struts IntelliJ IDEA Plugin 262.19039.1 released
Lukasz Lenart
[ANNOUNCE] Apache Groovy 5.0.8 Released
Paul King
[ANNOUNCE] Apache Groovy 4.0.33 Released
Paul King
[ANNOUNCE] Release Apache Paimon Rust 0.3.0
hope
[ANNOUNCE] Release Apache OpenDAL 0.58.1
Erick Guan
[ANNOUNCE] Apache Commons Validator 1.11.0
Gary Gregory
[ANNOUNCE] Apache Jena 6.2.0
Andy Seaborne
CVE-2026-62391: Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases
Akira Ajisaka
[ANNOUNCE] Apache Fory 1.5.0 released
Shawn Yang
[ANNOUNCEMENT] HttpComponents Client 5.6.3 Released
Oleg Kalnichevski
CVE-2026-66756: Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false
Tim Allison
CVE-2026-66755: Apache Tika: Arbitrary Local File Read in ISArchiveParser
Tim Allison
[ANNOUNCE] Apache ManifoldCF 2.31 released
Piergiorgio Lucidi
[CVE-2026-28811] Error Handling - Reveals Error Details
Juan Pablo Santos Rodríguez
[CVE-2026-28812] UserManager does not sanity-check user database at startup
Juan Pablo Santos Rodríguez
[CVE-2026-28813] JSPWiki vulnerable to JSON hijacking
Juan Pablo Santos Rodríguez
[CVE-2026-48910] Markdown parser allows XSS injection in Markdown error processing
Juan Pablo Santos Rodríguez
[CVE-2026-28814] Arbitrary Wiki Markup rendering due to lack of authentication
Juan Pablo Santos Rodríguez
[ANNOUNCE] Apache Commons Codec 1.22.1
Gary Gregory
CVE-2026-23985: Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser
Daniel Gaspar
CVE-2026-23981: Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modification
Daniel Gaspar
CVE-2026-52680: Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write
Akira Ajisaka
CVE-2026-44617: Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867
Jongyoul Lee
CVE-2026-44616: Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction
Jongyoul Lee
CVE-2026-44615: Apache Zeppelin: Path traversal in NotebookRepo note and folder path composition
Jongyoul Lee
CVE-2026-44613: Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling
Jongyoul Lee
[ANNOUNCE] Apache YuniKorn v1.9.0 released
Wilfred Spiegelenburg
[ANNOUNCE] Apache log4cxx 1.8.0 released
Stephen Webb
CVE-2026-23904: Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy
Akira Ajisaka
[ANNOUNCE] Apache Traffic Server 10.1.4 Release
Chris McFarlen
CVE-2026-50622: Apache Atlas: Missing Authorization on Admin Endpoints
Radhika Kundam
[SECURITY] CVE-2026-66299 Apache Tomcat - DoS via WebSocket chat example
Mark Thomas
[ANNOUNCE] Apache Kyuubi v1.12.0 is available
Cheng Pan
[ANNOUNCE] Apache Arrow ADBC 24 Released
David Li
[ANNOUNCE] Apache Airflow Providers prepared on 2026-07-22 are released
Shahar Epstein
CVE-2026-59243: Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
Shahar Epstein
[ANNOUNCE] Apache ActiveMQ 5.19.9 has been released!
Jean-Baptiste Onofré
[ANNOUNCE] Apache ActiveMQ 6.2.8 has been released!
Jean-Baptiste Onofré
[ANNOUNCE] Apache ActiveMQ 6.3.0 has been released!
Jean-Baptiste Onofré
CVE-2026-66713: Apache Axis2/Java: deserialization of untrusted Data
Robert Lazarski
CVE-2026-61487: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinations
Christopher L. Shannon
CVE-2026-59878: Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS
Christopher L. Shannon
CVE-2026-66391: Apache Wicket: leaked and missing CSP headers
Pedro Henrique Oliveira dos Santos
CVE-2026-66390: Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence
Pedro Henrique Oliveira dos Santos
[ANNOUNCE] Apache Wicket 10.10.0 released
Andrea Del Bene
[ANNOUNCE] Apache Pekko HTTP 1.4.0 released
PJ Fanning
[ANNOUNCE] Apache SystemDS 3.4.0
Jannik Lindemann
Earlier messages