announce
Thread
Date
Earlier messages
Later messages
Messages by Thread
CVE-2026-68075: Apache Qpid Broker-J: Incoming session flow control window can be exceeded
Daniil Kirilyuk
CVE-2026-68077: Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service
Daniil Kirilyuk
CVE-2026-68074: Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Daniil Kirilyuk
CVE-2026-68073: Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow
Daniil Kirilyuk
CVE-2026-68060: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication
Daniil Kirilyuk
[ANNOUNCE] Apache Qpid Proton-J 0.35.0 released
Robbie Gemmell
CVE-2026-66276: Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service
Robbie Gemmell
CVE-2026-66277: Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming delivery
Robbie Gemmell
CVE-2026-66275: Apache Qpid Proton-J: Incoming session flow control window can be exceeded
Robbie Gemmell
CVE-2026-66274: Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow
Robbie Gemmell
CVE-2026-66273: Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authentication
Robbie Gemmell
CVE-2026-66257: Apache Qpid Proton-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Robbie Gemmell
Apache Petri is now retired
Niall Pemberton
Apache ServiceMix is now retired
Niall Pemberton
[ANNOUNCE] Apache Groovy 6.0.0-beta-1 Released
Paul King
Fwd: [ANN] Apache Maven 4.0.0-rc-6 Released
Guillaume Nodet
CVE-2026-68981: Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests
David Handermann
CVE-2026-68980: Apache NiFi: Authorization Bypass for Parameter Context Asset Deletion
David Handermann
CVE-2026-62354: Apache NiFi: Incorrect Authorization for Parameter Context Validation Requests
David Handermann
CVE-2026-68979: Apache NiFi: Missing Authorization for Components Referenced by Parameter Context Updates
David Handermann
[ANNOUNCE] Apache Pulsar 4.2.4 released
Lari Hotari
[ANNOUNCE] Apache Pulsar 4.0.13 released
Lari Hotari
CVE-2026-61372: Apache Jena Fuseki: Web requests using SPARQL Update can escape file restrictions
Andy Seaborne
[ANNOUNCE] Apache NiFi 2.11.0 Released
Pierre Villard
[ANNOUNCE] Apache Polaris 1.7.0
Jean-Baptiste Onofré
Re: [ANNOUNCE] Apache Polaris 1.7.0
Alexandre Dutra
[ANNOUNCE] Apache StormCrawler 3.7.0 released
Davide Polato
[ANN] Apache Struts IntelliJ IDEA Plugin 262.19039.1 released
Lukasz Lenart
[ANNOUNCE] Apache Groovy 5.0.8 Released
Paul King
[ANNOUNCE] Apache Groovy 4.0.33 Released
Paul King
[ANNOUNCE] Release Apache Paimon Rust 0.3.0
hope
[ANNOUNCE] Release Apache OpenDAL 0.58.1
Erick Guan
[ANNOUNCE] Apache Commons Validator 1.11.0
Gary Gregory
[ANNOUNCE] Apache Jena 6.2.0
Andy Seaborne
CVE-2026-62391: Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases
Akira Ajisaka
[ANNOUNCE] Apache Fory 1.5.0 released
Shawn Yang
[ANNOUNCEMENT] HttpComponents Client 5.6.3 Released
Oleg Kalnichevski
CVE-2026-66756: Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false
Tim Allison
CVE-2026-66755: Apache Tika: Arbitrary Local File Read in ISArchiveParser
Tim Allison
[ANNOUNCE] Apache ManifoldCF 2.31 released
Piergiorgio Lucidi
[CVE-2026-28811] Error Handling - Reveals Error Details
Juan Pablo Santos Rodríguez
[CVE-2026-28812] UserManager does not sanity-check user database at startup
Juan Pablo Santos Rodríguez
[CVE-2026-28813] JSPWiki vulnerable to JSON hijacking
Juan Pablo Santos Rodríguez
[CVE-2026-48910] Markdown parser allows XSS injection in Markdown error processing
Juan Pablo Santos Rodríguez
[CVE-2026-28814] Arbitrary Wiki Markup rendering due to lack of authentication
Juan Pablo Santos Rodríguez
[ANNOUNCE] Apache Commons Codec 1.22.1
Gary Gregory
CVE-2026-23985: Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser
Daniel Gaspar
CVE-2026-23981: Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modification
Daniel Gaspar
CVE-2026-52680: Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write
Akira Ajisaka
CVE-2026-44617: Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867
Jongyoul Lee
CVE-2026-44616: Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction
Jongyoul Lee
CVE-2026-44615: Apache Zeppelin: Path traversal in NotebookRepo note and folder path composition
Jongyoul Lee
CVE-2026-44613: Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling
Jongyoul Lee
[ANNOUNCE] Apache YuniKorn v1.9.0 released
Wilfred Spiegelenburg
[ANNOUNCE] Apache log4cxx 1.8.0 released
Stephen Webb
CVE-2026-23904: Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy
Akira Ajisaka
[ANNOUNCE] Apache Traffic Server 10.1.4 Release
Chris McFarlen
CVE-2026-50622: Apache Atlas: Missing Authorization on Admin Endpoints
Radhika Kundam
[SECURITY] CVE-2026-66299 Apache Tomcat - DoS via WebSocket chat example
Mark Thomas
[ANNOUNCE] Apache Kyuubi v1.12.0 is available
Cheng Pan
[ANNOUNCE] Apache Arrow ADBC 24 Released
David Li
[ANNOUNCE] Apache Airflow Providers prepared on 2026-07-22 are released
Shahar Epstein
CVE-2026-59243: Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
Shahar Epstein
[ANNOUNCE] Apache ActiveMQ 5.19.9 has been released!
Jean-Baptiste Onofré
[ANNOUNCE] Apache ActiveMQ 6.2.8 has been released!
Jean-Baptiste Onofré
[ANNOUNCE] Apache ActiveMQ 6.3.0 has been released!
Jean-Baptiste Onofré
CVE-2026-66713: Apache Axis2/Java: deserialization of untrusted Data
Robert Lazarski
CVE-2026-61487: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinations
Christopher L. Shannon
CVE-2026-59878: Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS
Christopher L. Shannon
CVE-2026-66391: Apache Wicket: leaked and missing CSP headers
Pedro Henrique Oliveira dos Santos
CVE-2026-66390: Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence
Pedro Henrique Oliveira dos Santos
[ANNOUNCE] Apache Wicket 10.10.0 released
Andrea Del Bene
[ANNOUNCE] Apache Pekko HTTP 1.4.0 released
PJ Fanning
[ANNOUNCE] Apache SystemDS 3.4.0
Jannik Lindemann
CVE-2026-66053: Apache Thrift: Python TSSLSocket Hostname Matcher Import
Jens Geyer
CVE-2026-58662: Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass
Jens Geyer
CVE-2026-58023: Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path
Jens Geyer
CVE-2026-58389: Apache Thrift: Rust binary protocol non-strict path missing string size limit
Jens Geyer
CVE-2026-55970: Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat()
Jens Geyer
CVE-2026-55971: Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()
Jens Geyer
CVE-2026-55968: Apache Thrift: Node.js quadratic-time DoS in server receive transports
Jens Geyer
CVE-2026-49158: Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb
Jens Geyer
CVE-2026-55969: Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
Jens Geyer
CVE-2026-48145: Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass
Jens Geyer
CVE-2026-48586: Apache Thrift: TZlibTransport Decompression Size Limit
Jens Geyer
CVE-2026-48144: Apache Thrift: c_glib TLS Client Missing Hostname Verification
Jens Geyer
CVE-2026-45112: Apache Thrift: Unbounded Read Leading to Denial of Service
Jens Geyer
CVE-2026-43871: Apache Thrift: TCompactProtocol varint byte-count limit
Jens Geyer
CVE-2026-41608: Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport
Jens Geyer
CVE-2026-49326: Apache HBase: Missing scanner instance owner check in thrift delegation service
Duo Zhang
CVE-2026-46452: Apache NimBLE: Mesh Proxy SAR reassembly unbounded append and unchecked failure
Szymon Janc
CVE-2026-45815: Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler
Szymon Janc
CVE-2026-45816: Apache NimBLE: NULL pointer dereference vulnerability in SMP LTK request
Szymon Janc
CVE-2026-45811: Apache NimBLE: Buffer overflow in socket HCI transport
Szymon Janc
CVE-2026-45813: Apache NimBLE: Incorrect data validation in BASS add/modify source operation
Szymon Janc
CVE-2026-45812: Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler
Szymon Janc
CVE-2026-66144: Apache Neethi: Remote PolicyReference fetch lacks resource bounds
Colm O hEigeartaigh
CVE-2026-66143: Apache Neethi: Missing global alternative-output budget across policy computation paths
Colm O hEigeartaigh
CVE-2026-66142: Apache Neethi: Uncontrolled recursion in policy processing
Colm O hEigeartaigh
[ANNOUNCE] Grails Publish Gradle Plugin 1.0.0-M2
Mattias Reichel
[ANN] Maven Resolver 2.0.21 Released
Tamás Cservenák
[ANNOUNCE] Apache Grails GitHub Actions 1.0.3
Mattias Reichel
[ANNOUNCE] OpenNLP 2.5.11 and 3.0.0-M5 released
Richard Zowalla
CVE-2026-63317: Apache OpenNLP: Arbitrary Class Instantiation in GeneratorFactory via Feature Descriptor XML
Richard Zowalla
[ANNOUNCE] Apache TsFile 2.4.0 released
Haonan Hou
[ANNOUNCE] Apache Storm 2.8.9 and 3.0.0 Released (Storm 2.x End of Life)
Rui Abreu
[ANN] Maven JAR Plugin 3.5.1 Released
Tamás Cservenák
[ANNOUNCE] Apache Tika 3.3.2 released
Tim Allison
[ANNOUNCE] Release of Apache Doris Operator 26.0.0
Mingyu Chen
[ANNOUNCE] Apache Arrow Go v18.7.0 Released
Matt Topol
[ANNOUNCE] Apache Answer 2.0.2 released
Robin Ren
[ANNOUNCE] Apache Mynewt 1.15.0 and Apache Mynewt NimBLE 1.10.0 released
Szymon Janc
[ANN] Maven Resolver Ant Tasks 1.6.1 released
Tamás Cservenák
[ANNOUNCE] Apache Arrow 25.0.0 released
Raúl Cumplido
[ANNOUNCE] Apache Arrow JS 21.2.0 released
Sutou Kouhei
CVE-2026-60080: Apache Fory: Rust MetaString heap use-after-free
Chaokun Yang
CVE-2026-64606: Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interface
Chaokun Yang
CVE-2026-64608: Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatible-mode field-skip paths
Chaokun Yang
CVE-2026-64609: Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deserialization
Chaokun Yang
CVE-2026-58624: Apache MINA SSHD: Remote execution of JGit commands can write files on the server
Thomas Wolf
CVE-2026-56624: Apache MINA SSHD: SSH certificate options lack validations
Thomas Wolf
CVE-2026-56623: Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on Windows
Thomas Wolf
CVE-2026-56452: Apache MINA SSHD: Path traversal in SCP file reception
Thomas Wolf
[ANNOUNCE] Apache Pulsar Go Client 0.21.0 released
Zike Yang
[ANN] Apache Syncope 4.0.7
Francesco Chicchiriccò
[ANN] Apache Syncope 4.1.2
Francesco Chicchiriccò
[ANNOUNCE] Apache Fory 1.4.0 released
Shawn Yang
CVE-2026-63071: Apache Syncope: RCE via Groovy Sandbox bypass
Francesco Chicchiriccò
CVE-2026-62418: Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check
Francesco Chicchiriccò
CVE-2026-62183: Apache Syncope: User self-service privilege escalation
Francesco Chicchiriccò
CVE-2026-57308: Apache Syncope: SQL injection vulnerability in Audit Events search
Francesco Chicchiriccò
CVE-2026-53421: Apache Syncope: Remote Code Execution via Scripted Connector
Francesco Chicchiriccò
CVE-2026-53405: Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask
Francesco Chicchiriccò
[ANNOUNCE] Apache Auron (Incubating) v8.0.0 available
slfan1989
[ANNOUNCE] Apache Magpie 0.1.0 released
Jarek Potiuk
[ANNOUNCE] Apache HBase 3.0.0-beta-2 is now available for download
Duo Zhang
[ANN] Apache TomEE 10.2.0
Richard Zowalla
[ANNOUNCE] Apache Accumulo 2.1.6
Christopher
[ANNOUNCE] Apache Traffic Server 10.1.3 Release
Chris McFarlen
CVE-2026-62764: Apache Accumulo: A user can trigger a graceful shutdown of services without the relevant system permissions
Christopher Tubbs
[ANNOUNCE] Release Apache OpenDAL 0.58.0
Xuanwo
CVE-2026-26032: Apache Ivy: PackagerResolver path traversal vulnerability
Stefan Bodewig
[ANN] Apache Ivy 2.6.0 Released
Stefan Bodewig
[ANNOUNCE] Apache PDFBox 2.0.37 released
Andreas Lehmkühler
[ANNOUNCE] Apache Jackrabbit Oak 2.4.0 released
Julian Reschke
[ANNOUNCE] Apache Grails 7.0.14
James Daugherty
[ANNOUNCE] Apache Grails 7.1.4
James Daugherty
[ANNOUNCE] Apache Grails 7.2.1
James Daugherty
[ANNOUNCE] Apache Fineract 1.15.0 Release
Adam Monsen
CVE-2026-57821: Apache Fineract: Office list: SQL Injection via Subquery in orderBy
Terence Monteiro
CVE-2026-35152: Apache Fineract: SQL injection in runreports endpoint
Terence Monteiro
CVE-2026-56287: Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosure
Terence Monteiro
[ANNOUNCE] Apache OpenMeetings 9.1.0 is released
Maxim Solodovnik
CVE-2026-49488: Apache OpenMeetings: Arbitrary File Read
Maxim Solodovnik
[SECURITY] CVE-2026-59084 Apache Tomcat - EncryptInterceptor requirements not clearly documented
Mark Thomas
[SECURITY] CVE-2026-59083 Apache Tomcat - Incorrect URL decoding in RewriteValve may allow security control bypass
Mark Thomas
CVE-2026-62393: Apache Kylin: Improper authorization in job information retrieval
Li Yang
CVE-2026-62392: Apache Kylin: OS Command Injection via Async Query API
Li Yang
CVE-2026-62390: Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API
Li Yang
CVE-2026-58319: Apache Doris: Improper Authentication in Frontend HTTP API
Mingyu Chen
CVE-2026-59245: Apache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the global all-DAGs permission (access_control privilege escalation via resource_name() collision)
Vincent Beck
CVE-2026-58065: Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification
Vincent Beck
[ANNOUNCE] Apache Pulsar Helm Chart version 4.7.0 Released
Lari Hotari
[ANN] ASF Maven 3.10.0-rc-1 released
Tamás Cservenák
[ANN] Apache Struts IntelliJ IDEA Plugin 261.19027.1 released
Lukasz Lenart
CVE-2026-49876: Apache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs
Yu Qi
CVE-2026-41041: Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended API endpoints.
Jerry Shao
[ANNOUNCE] Apache PDFBox 3.0.8 released
Andreas Lehmkühler
CVE-2026-49844: Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()
Piotr Karwasz
[ANNOUNCE] Apache Airflow Providers prepared on 2026-07-06 are released
Vincent Beck
[ANN] Apache Tomcat 10.1.57 Available
Christopher Schultz
[ANNOUNCE] Apache Polaris 1.6.0 has been released!
Jean-Baptiste Onofré
CVE-2026-40454: Apache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server data
Haonan Hou
CVE-2026-40452: Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users
Haonan Hou
CVE-2026-40009: Apache IoTDB: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor
Haonan Hou
CVE-2026-40008: Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC
Haonan Hou
CVE-2026-40008: Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC
Haonan Hou
CVE-2026-40007: Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError
Haonan Hou
CVE-2026-40006: Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver
Haonan Hou
CVE-2026-40005: Apache IoTDB: Path Traversal in Pipe File Transfer Receiver
Haonan Hou
CVE-2026-28564: Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials
Haonan Hou
[ANNOUNCE] Apache MINA SSHD 3.0.0-M5 released
Thomas Wolf
[ANNOUNCE] Apache MINA SSHD 2.19.0 released
Thomas Wolf
[ANNOUNCE] Apache IoTDB 2.0.10 released
Haonan Hou
[ANNOUNCE] Apache Accumulo 2.1.5
Christopher
CVE-2026-57111: Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-Origin
Junkai Xue
CVE-2026-41042: Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter
Jerry Shao
[ANN] Apache Tomcat 11.0.24 Available
Mark Thomas
[ANN] Apache Tomcat 9.0.120 available
Rémy Maucherat
[ANNOUNCE] Apache Daffodil 4.2.0 Released
Olabusayo Kilo
[ANNOUNCE] Apache Daffodil 4.2.0 Released
Olabusayo Kilo
[ANNOUNCE] Apache Airflow 3.3.0 Released
Rahul Vats
CVE-2026-48892: Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic options
Rahul Vats
CVE-2026-48891: Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.target
Rahul Vats
CVE-2026-49296: Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagSources/{dag_id}
Rahul Vats
CVE-2026-48828: Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key
Rahul Vats
CVE-2026-49487: Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs
Rahul Vats
CVE-2026-33264: Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize()
Rahul Vats
CVE-2026-43825: Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel
Richard Zowalla
[ANNOUNCE] Apache Jackrabbit 2.23.5-beta released
Manfred Baedke
Earlier messages
Later messages