announce
Thread
Date
Earlier messages
Later messages
Messages by Date
2026/08/06
CVE-2026-66909: Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage
Colm O hEigeartaigh
2026/08/06
CVE-2026-65432: Apache CXF: XXE via WSDL/XSD import parsing
Colm O hEigeartaigh
2026/08/06
CVE-2026-64958: Apache CXF: Denial of service via message header attachments
Colm O hEigeartaigh
2026/08/06
CVE-2026-57819: Apache CXF: No default restriction on the amount of form parameters per message
Colm O hEigeartaigh
2026/08/06
CVE-2026-54225: Apache CXF: Denial of Service attack via large attachments
Colm O hEigeartaigh
2026/08/06
CVE-2026-64640: Apache Polaris: register endpoint reads attacker-controlled storage location before allowed-locations validation
Alexandre Dutra
2026/08/05
[ANNOUNCE] Apache HBase 3.0.0 is now available for download
Duo Zhang
2026/08/05
CVE-2026-60053: Apache Answer: Residual Administrative API Key Access After Role or Account Revocation
Enxin Xie
2026/08/05
CVE-2026-48912: Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL
Enxin Xie
2026/08/05
CVE-2026-60023: Apache Answer: Unauthorized disclosure of deleted or pending answer content
Enxin Xie
2026/08/05
CVE-2026-50749: Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions
Enxin Xie
2026/08/05
CVE-2026-48911: Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow
Enxin Xie
2026/08/05
CVE-2026-48834: Apache Answer: Denial of service via crafted Accept-Language header parsing
Enxin Xie
2026/08/05
[ANNOUNCE] Apache Sedona 1.9.1 released
Jia Yu
2026/08/04
CVE-2026-61486: Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input
Piotr Karwasz
2026/08/04
CVE-2026-61485: Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index
Piotr Karwasz
2026/08/04
CVE-2026-61484: Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS
Piotr Karwasz
2026/08/04
CVE-2026-61483: Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow DoS
Piotr Karwasz
2026/08/04
[ANNOUNCE] Apache BVal 3.1.0
Markus Jung
2026/08/04
[ANNOUNCE] Apache Qpid protonj2 1.2.0 released
Timothy Bish
2026/08/04
CVE-2026-67592: Apache Qpid ProtonJ2: Unable to govern the maximum number of transfer frames per incoming delivery
Timothy A. Bish
2026/08/04
CVE-2026-67591: Apache Qpid ProtonJ2: Incoming session flow control window can be exceeded
Timothy A. Bish
2026/08/04
CVE-2026-67590: Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflow
Timothy A. Bish
2026/08/04
CVE-2026-67589: Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-authentication
Timothy A. Bish
2026/08/04
CVE-2026-67588: Apache Qpid ProtonJ2: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Timothy A. Bish
2026/08/04
CVE-2026-67553: Apache Qpid Proton Dotnet: Incoming session flow control window can be exceeded
Timothy A. Bish
2026/08/04
CVE-2026-67555: Apache Qpid Proton Dotnet: Unable to govern the maximum number of transfer frames per incoming delivery
Timothy A. Bish
2026/08/04
CVE-2026-67554: Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of service
Timothy A. Bish
2026/08/04
CVE-2026-67552: Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stackoverflow
Timothy A. Bish
2026/08/04
CVE-2026-67551: Apache Qpid Proton Dotnet: Type size/count handling can lead to excessive allocation pre-authentication
Timothy A. Bish
2026/08/04
CVE-2026-67465: Apache Qpid Proton Dotnet: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Timothy A. Bish
2026/08/04
CVE-2026-68080: Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service
Daniil Kirilyuk
2026/08/04
CVE-2026-68078: Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery
Daniil Kirilyuk
2026/08/04
CVE-2026-68075: Apache Qpid Broker-J: Incoming session flow control window can be exceeded
Daniil Kirilyuk
2026/08/04
CVE-2026-68077: Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service
Daniil Kirilyuk
2026/08/04
CVE-2026-68074: Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Daniil Kirilyuk
2026/08/04
CVE-2026-68073: Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow
Daniil Kirilyuk
2026/08/04
CVE-2026-68060: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication
Daniil Kirilyuk
2026/08/04
[ANNOUNCE] Apache Qpid Proton-J 0.35.0 released
Robbie Gemmell
2026/08/04
CVE-2026-66276: Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service
Robbie Gemmell
2026/08/04
CVE-2026-66277: Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming delivery
Robbie Gemmell
2026/08/04
CVE-2026-66275: Apache Qpid Proton-J: Incoming session flow control window can be exceeded
Robbie Gemmell
2026/08/04
CVE-2026-66274: Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow
Robbie Gemmell
2026/08/04
CVE-2026-66273: Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authentication
Robbie Gemmell
2026/08/04
CVE-2026-66257: Apache Qpid Proton-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Robbie Gemmell
2026/08/04
Apache Petri is now retired
Niall Pemberton
2026/08/04
Apache ServiceMix is now retired
Niall Pemberton
2026/08/04
[ANNOUNCE] Apache Groovy 6.0.0-beta-1 Released
Paul King
2026/08/03
Fwd: [ANN] Apache Maven 4.0.0-rc-6 Released
Guillaume Nodet
2026/08/03
CVE-2026-68981: Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests
David Handermann
2026/08/03
CVE-2026-68980: Apache NiFi: Authorization Bypass for Parameter Context Asset Deletion
David Handermann
2026/08/03
CVE-2026-62354: Apache NiFi: Incorrect Authorization for Parameter Context Validation Requests
David Handermann
2026/08/03
CVE-2026-68979: Apache NiFi: Missing Authorization for Components Referenced by Parameter Context Updates
David Handermann
2026/08/03
[ANNOUNCE] Apache Pulsar 4.2.4 released
Lari Hotari
2026/08/03
[ANNOUNCE] Apache Pulsar 4.0.13 released
Lari Hotari
2026/08/03
CVE-2026-61372: Apache Jena Fuseki: Web requests using SPARQL Update can escape file restrictions
Andy Seaborne
2026/08/03
Re: [ANNOUNCE] Apache Polaris 1.7.0
Alexandre Dutra
2026/08/03
[ANNOUNCE] Apache NiFi 2.11.0 Released
Pierre Villard
2026/08/02
[ANNOUNCE] Apache Polaris 1.7.0
Jean-Baptiste Onofré
2026/08/02
[ANNOUNCE] Apache StormCrawler 3.7.0 released
Davide Polato
2026/08/01
[ANN] Apache Struts IntelliJ IDEA Plugin 262.19039.1 released
Lukasz Lenart
2026/07/31
[ANNOUNCE] Apache Groovy 5.0.8 Released
Paul King
2026/07/31
[ANNOUNCE] Apache Groovy 4.0.33 Released
Paul King
2026/07/31
[ANNOUNCE] Release Apache Paimon Rust 0.3.0
hope
2026/07/31
[ANNOUNCE] Release Apache OpenDAL 0.58.1
Erick Guan
2026/07/31
[ANNOUNCE] Apache Commons Validator 1.11.0
Gary Gregory
2026/07/31
[ANNOUNCE] Apache Jena 6.2.0
Andy Seaborne
2026/07/31
CVE-2026-62391: Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases
Akira Ajisaka
2026/07/31
[ANNOUNCE] Apache Fory 1.5.0 released
Shawn Yang
2026/07/31
[ANNOUNCEMENT] HttpComponents Client 5.6.3 Released
Oleg Kalnichevski
2026/07/30
CVE-2026-66756: Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false
Tim Allison
2026/07/30
CVE-2026-66755: Apache Tika: Arbitrary Local File Read in ISArchiveParser
Tim Allison
2026/07/30
[ANNOUNCE] Apache ManifoldCF 2.31 released
Piergiorgio Lucidi
2026/07/30
[CVE-2026-28811] Error Handling - Reveals Error Details
Juan Pablo Santos Rodríguez
2026/07/30
[CVE-2026-28812] UserManager does not sanity-check user database at startup
Juan Pablo Santos Rodríguez
2026/07/30
[CVE-2026-28813] JSPWiki vulnerable to JSON hijacking
Juan Pablo Santos Rodríguez
2026/07/30
[CVE-2026-48910] Markdown parser allows XSS injection in Markdown error processing
Juan Pablo Santos Rodríguez
2026/07/30
[CVE-2026-28814] Arbitrary Wiki Markup rendering due to lack of authentication
Juan Pablo Santos Rodríguez
2026/07/30
[ANNOUNCE] Apache Commons Codec 1.22.1
Gary Gregory
2026/07/30
CVE-2026-23985: Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser
Daniel Gaspar
2026/07/30
CVE-2026-23981: Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modification
Daniel Gaspar
2026/07/30
CVE-2026-52680: Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write
Akira Ajisaka
2026/07/30
CVE-2026-44617: Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867
Jongyoul Lee
2026/07/29
CVE-2026-44616: Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction
Jongyoul Lee
2026/07/29
CVE-2026-44615: Apache Zeppelin: Path traversal in NotebookRepo note and folder path composition
Jongyoul Lee
2026/07/29
CVE-2026-44613: Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling
Jongyoul Lee
2026/07/29
[ANNOUNCE] Apache YuniKorn v1.9.0 released
Wilfred Spiegelenburg
2026/07/29
[ANNOUNCE] Apache log4cxx 1.8.0 released
Stephen Webb
2026/07/28
CVE-2026-23904: Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy
Akira Ajisaka
2026/07/28
[ANNOUNCE] Apache Traffic Server 10.1.4 Release
Chris McFarlen
2026/07/28
CVE-2026-50622: Apache Atlas: Missing Authorization on Admin Endpoints
Radhika Kundam
2026/07/28
[SECURITY] CVE-2026-66299 Apache Tomcat - DoS via WebSocket chat example
Mark Thomas
2026/07/28
[ANNOUNCE] Apache Kyuubi v1.12.0 is available
Cheng Pan
2026/07/28
[ANNOUNCE] Apache Arrow ADBC 24 Released
David Li
2026/07/28
[ANNOUNCE] Apache Airflow Providers prepared on 2026-07-22 are released
Shahar Epstein
2026/07/28
CVE-2026-59243: Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
Shahar Epstein
2026/07/27
[ANNOUNCE] Apache ActiveMQ 5.19.9 has been released!
Jean-Baptiste Onofré
2026/07/27
[ANNOUNCE] Apache ActiveMQ 6.2.8 has been released!
Jean-Baptiste Onofré
2026/07/27
[ANNOUNCE] Apache ActiveMQ 6.3.0 has been released!
Jean-Baptiste Onofré
2026/07/27
CVE-2026-66713: Apache Axis2/Java: deserialization of untrusted Data
Robert Lazarski
2026/07/27
CVE-2026-61487: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinations
Christopher L. Shannon
2026/07/27
CVE-2026-59878: Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS
Christopher L. Shannon
2026/07/27
CVE-2026-66391: Apache Wicket: leaked and missing CSP headers
Pedro Henrique Oliveira dos Santos
2026/07/27
CVE-2026-66390: Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence
Pedro Henrique Oliveira dos Santos
2026/07/27
[ANNOUNCE] Apache Wicket 10.10.0 released
Andrea Del Bene
2026/07/26
[ANNOUNCE] Apache Pekko HTTP 1.4.0 released
PJ Fanning
2026/07/25
[ANNOUNCE] Apache SystemDS 3.4.0
Jannik Lindemann
2026/07/24
CVE-2026-66053: Apache Thrift: Python TSSLSocket Hostname Matcher Import
Jens Geyer
2026/07/24
CVE-2026-58662: Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass
Jens Geyer
2026/07/24
CVE-2026-58023: Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path
Jens Geyer
2026/07/24
CVE-2026-58389: Apache Thrift: Rust binary protocol non-strict path missing string size limit
Jens Geyer
2026/07/24
CVE-2026-55970: Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat()
Jens Geyer
2026/07/24
CVE-2026-55971: Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()
Jens Geyer
2026/07/24
CVE-2026-55968: Apache Thrift: Node.js quadratic-time DoS in server receive transports
Jens Geyer
2026/07/24
CVE-2026-49158: Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb
Jens Geyer
2026/07/24
CVE-2026-55969: Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
Jens Geyer
2026/07/24
CVE-2026-48145: Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass
Jens Geyer
2026/07/24
CVE-2026-48586: Apache Thrift: TZlibTransport Decompression Size Limit
Jens Geyer
2026/07/24
CVE-2026-48144: Apache Thrift: c_glib TLS Client Missing Hostname Verification
Jens Geyer
2026/07/24
CVE-2026-45112: Apache Thrift: Unbounded Read Leading to Denial of Service
Jens Geyer
2026/07/24
CVE-2026-43871: Apache Thrift: TCompactProtocol varint byte-count limit
Jens Geyer
2026/07/24
CVE-2026-41608: Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport
Jens Geyer
2026/07/24
CVE-2026-49326: Apache HBase: Missing scanner instance owner check in thrift delegation service
Duo Zhang
2026/07/24
CVE-2026-46452: Apache NimBLE: Mesh Proxy SAR reassembly unbounded append and unchecked failure
Szymon Janc
2026/07/24
CVE-2026-45815: Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler
Szymon Janc
2026/07/24
CVE-2026-45816: Apache NimBLE: NULL pointer dereference vulnerability in SMP LTK request
Szymon Janc
2026/07/24
CVE-2026-45811: Apache NimBLE: Buffer overflow in socket HCI transport
Szymon Janc
2026/07/24
CVE-2026-45813: Apache NimBLE: Incorrect data validation in BASS add/modify source operation
Szymon Janc
2026/07/24
CVE-2026-45812: Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler
Szymon Janc
2026/07/24
CVE-2026-66144: Apache Neethi: Remote PolicyReference fetch lacks resource bounds
Colm O hEigeartaigh
2026/07/24
CVE-2026-66143: Apache Neethi: Missing global alternative-output budget across policy computation paths
Colm O hEigeartaigh
2026/07/24
CVE-2026-66142: Apache Neethi: Uncontrolled recursion in policy processing
Colm O hEigeartaigh
2026/07/24
[ANNOUNCE] Grails Publish Gradle Plugin 1.0.0-M2
Mattias Reichel
2026/07/24
[ANN] Maven Resolver 2.0.21 Released
Tamás Cservenák
2026/07/24
[ANNOUNCE] Apache Grails GitHub Actions 1.0.3
Mattias Reichel
2026/07/24
[ANNOUNCE] OpenNLP 2.5.11 and 3.0.0-M5 released
Richard Zowalla
2026/07/24
CVE-2026-63317: Apache OpenNLP: Arbitrary Class Instantiation in GeneratorFactory via Feature Descriptor XML
Richard Zowalla
2026/07/23
[ANNOUNCE] Apache TsFile 2.4.0 released
Haonan Hou
2026/07/23
[ANNOUNCE] Apache Storm 2.8.9 and 3.0.0 Released (Storm 2.x End of Life)
Rui Abreu
2026/07/22
[ANN] Maven JAR Plugin 3.5.1 Released
Tamás Cservenák
2026/07/22
[ANNOUNCE] Apache Tika 3.3.2 released
Tim Allison
2026/07/21
[ANNOUNCE] Release of Apache Doris Operator 26.0.0
Mingyu Chen
2026/07/21
[ANNOUNCE] Apache Arrow Go v18.7.0 Released
Matt Topol
2026/07/21
[ANNOUNCE] Apache Answer 2.0.2 released
Robin Ren
2026/07/21
[ANNOUNCE] Apache Mynewt 1.15.0 and Apache Mynewt NimBLE 1.10.0 released
Szymon Janc
2026/07/21
[ANN] Maven Resolver Ant Tasks 1.6.1 released
Tamás Cservenák
2026/07/21
[ANNOUNCE] Apache Arrow 25.0.0 released
Raúl Cumplido
2026/07/21
[ANNOUNCE] Apache Arrow JS 21.2.0 released
Sutou Kouhei
2026/07/21
CVE-2026-60080: Apache Fory: Rust MetaString heap use-after-free
Chaokun Yang
2026/07/21
CVE-2026-64606: Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interface
Chaokun Yang
2026/07/21
CVE-2026-64608: Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatible-mode field-skip paths
Chaokun Yang
2026/07/21
CVE-2026-64609: Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deserialization
Chaokun Yang
2026/07/20
CVE-2026-58624: Apache MINA SSHD: Remote execution of JGit commands can write files on the server
Thomas Wolf
2026/07/20
CVE-2026-56624: Apache MINA SSHD: SSH certificate options lack validations
Thomas Wolf
2026/07/20
CVE-2026-56623: Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on Windows
Thomas Wolf
2026/07/20
CVE-2026-56452: Apache MINA SSHD: Path traversal in SCP file reception
Thomas Wolf
2026/07/20
[ANNOUNCE] Apache Pulsar Go Client 0.21.0 released
Zike Yang
2026/07/20
[ANN] Apache Syncope 4.0.7
Francesco Chicchiriccò
2026/07/20
[ANN] Apache Syncope 4.1.2
Francesco Chicchiriccò
2026/07/20
[ANNOUNCE] Apache Fory 1.4.0 released
Shawn Yang
2026/07/20
CVE-2026-63071: Apache Syncope: RCE via Groovy Sandbox bypass
Francesco Chicchiriccò
2026/07/20
CVE-2026-62418: Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check
Francesco Chicchiriccò
2026/07/20
CVE-2026-62183: Apache Syncope: User self-service privilege escalation
Francesco Chicchiriccò
2026/07/20
CVE-2026-57308: Apache Syncope: SQL injection vulnerability in Audit Events search
Francesco Chicchiriccò
2026/07/20
CVE-2026-53421: Apache Syncope: Remote Code Execution via Scripted Connector
Francesco Chicchiriccò
2026/07/20
CVE-2026-53405: Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask
Francesco Chicchiriccò
2026/07/19
[ANNOUNCE] Apache Auron (Incubating) v8.0.0 available
slfan1989
2026/07/19
[ANNOUNCE] Apache Magpie 0.1.0 released
Jarek Potiuk
2026/07/18
[ANNOUNCE] Apache HBase 3.0.0-beta-2 is now available for download
Duo Zhang
2026/07/17
[ANN] Apache TomEE 10.2.0
Richard Zowalla
2026/07/17
[ANNOUNCE] Apache Accumulo 2.1.6
Christopher
2026/07/17
[ANNOUNCE] Apache Traffic Server 10.1.3 Release
Chris McFarlen
2026/07/16
CVE-2026-62764: Apache Accumulo: A user can trigger a graceful shutdown of services without the relevant system permissions
Christopher Tubbs
2026/07/16
[ANNOUNCE] Release Apache OpenDAL 0.58.0
Xuanwo
2026/07/15
CVE-2026-26032: Apache Ivy: PackagerResolver path traversal vulnerability
Stefan Bodewig
2026/07/15
[ANN] Apache Ivy 2.6.0 Released
Stefan Bodewig
2026/07/15
[ANNOUNCE] Apache PDFBox 2.0.37 released
Andreas Lehmkühler
2026/07/15
[ANNOUNCE] Apache Jackrabbit Oak 2.4.0 released
Julian Reschke
2026/07/15
[ANNOUNCE] Apache Grails 7.0.14
James Daugherty
2026/07/15
[ANNOUNCE] Apache Grails 7.1.4
James Daugherty
2026/07/15
[ANNOUNCE] Apache Grails 7.2.1
James Daugherty
2026/07/15
[ANNOUNCE] Apache Fineract 1.15.0 Release
Adam Monsen
2026/07/14
CVE-2026-57821: Apache Fineract: Office list: SQL Injection via Subquery in orderBy
Terence Monteiro
2026/07/14
CVE-2026-35152: Apache Fineract: SQL injection in runreports endpoint
Terence Monteiro
2026/07/14
CVE-2026-56287: Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosure
Terence Monteiro
2026/07/14
[ANNOUNCE] Apache OpenMeetings 9.1.0 is released
Maxim Solodovnik
2026/07/14
CVE-2026-49488: Apache OpenMeetings: Arbitrary File Read
Maxim Solodovnik
2026/07/14
[SECURITY] CVE-2026-59084 Apache Tomcat - EncryptInterceptor requirements not clearly documented
Mark Thomas
2026/07/14
[SECURITY] CVE-2026-59083 Apache Tomcat - Incorrect URL decoding in RewriteValve may allow security control bypass
Mark Thomas
2026/07/13
CVE-2026-62393: Apache Kylin: Improper authorization in job information retrieval
Li Yang
2026/07/13
CVE-2026-62392: Apache Kylin: OS Command Injection via Async Query API
Li Yang
2026/07/13
CVE-2026-62390: Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API
Li Yang
2026/07/13
CVE-2026-58319: Apache Doris: Improper Authentication in Frontend HTTP API
Mingyu Chen
2026/07/13
CVE-2026-59245: Apache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the global all-DAGs permission (access_control privilege escalation via resource_name() collision)
Vincent Beck
2026/07/13
CVE-2026-58065: Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification
Vincent Beck
2026/07/13
[ANNOUNCE] Apache Pulsar Helm Chart version 4.7.0 Released
Lari Hotari
2026/07/13
[ANN] ASF Maven 3.10.0-rc-1 released
Tamás Cservenák
2026/07/13
[ANN] Apache Struts IntelliJ IDEA Plugin 261.19027.1 released
Lukasz Lenart
2026/07/12
CVE-2026-49876: Apache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs
Yu Qi
2026/07/12
CVE-2026-41041: Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended API endpoints.
Jerry Shao
Earlier messages
Later messages