Messages by Thread
-
[ANN] Apache Tomcat Migration tool for Jakarta EE 1.0.12
Mark Thomas
-
[ANNOUNCE] Apache Airflow Helm Chart version 1.22.0 Released
Jarek Potiuk
-
[ANNOUNCE] Release Apache Paimon Mosaic 0.1.0
hope
-
[ANN] Apache CycloneDX Antlib 0.1 Released
Stefan Bodewig
-
CVE-2026-50076: Apache Fory: Java ReplaceResolverSerializer deserialization checks bypass
Chaokun Yang
-
[ANNOUNCE] Release Apache Paimon Rust 0.2.0
yuxia luo
-
Apache MINA 2.0.29, 2.0.13 and 2.2.8 release
Emmanuel Lecharny
-
[ANNOUNCE] Apache Jackrabbit Oak 2.2.0 released
Julian Reschke
-
CVE-2026-41115: Apache Kafka: Improper Authorization in CONSUMER_GROUP_DESCRIBE API
Luke Chen
-
CVE-2026-46718: Apache Calcite: A user-controled model can load arbitrary classes, leading to code execution
Julian Hyde
-
[ANNOUNCE] Apache APISIX Ingress controller v2.1.0 released
Xin Rong
-
[ANNOUNCE] Apache Fory 1.1.0 released
Shawn Yang
-
[ANNOUNCE] Release Apache OpenDAL 0.57.0
Xuanwo
-
CVE-2026-49328: Apache Fesod (Incubating): Improper validation of user-supplied URLs leading to SSRF
Shuxin Pan
-
CVE-2026-45192: Apache Airflow: Incomplete Redaction of Sensitive Fields in Connection Extra API Response
Rahul Vats
-
CVE-2026-35563: Apache Directory LDAP API: LDAP client implementation does not verify if the server certificate matches the intended LDAP hostname
Emmanuel Lécharny
-
CVE-2026-49270: Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Durable Subscription Disclosure via Crafted BrokerInfo (OpenWire)
Christopher L. Shannon
-
CVE-2026-49157: Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default
Christopher L. Shannon
-
CVE-2026-46605: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incomplete authorization during destination removal
Christopher L. Shannon
-
CVE-2026-45505: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia `addNetworkConnector` Discovery Wrapper Bypass
Christopher L. Shannon
-
CVE-2026-42588: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector
Christopher L. Shannon
-
CVE-2026-42253: Apache ActiveMQ, Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Properties
Christopher L. Shannon
-
CVE-2026-49298: Apache Airflow: JWT Token Exposure in KubernetesExecutor Command-Line Arguments
Rahul Vats
-
CVE-2026-48726: Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logout path
Rahul Vats
-
CVE-2026-46764: Apache Airflow: Event Log detail endpoint bypasses DAG-scoped event log permission filter
Rahul Vats
-
CVE-2026-45426: Apache Airflow: Log server JWT authorization bypass via Python lstrip() character stripping allows cross-Dag log access
Rahul Vats
-
CVE-2026-45360: Apache Airflow: Arbitrary import in custom deadline-reference deserialization
Rahul Vats
-
CVE-2026-42359: Apache Airflow: Authenticated RCE via XCom PATCH endpoint — XComUpdateBody missing FORBIDDEN_XCOM_KEYS validator
Rahul Vats
-
CVE-2026-42358: Apache Airflow: Variable masker depth-limit bypass returns cleartext nested secrets
Rahul Vats
-
CVE-2026-42360: Apache Airflow: Rendered template truncation bypasses nested sensitive-key masking
Rahul Vats
-
CVE-2026-42252: Apache Airflow: BashOperator Jinja2 injection via dag_run.conf — low-privilege user pattern
Rahul Vats
-
CVE-2026-41084: Apache Airflow: API authorization bypass: bulk TaskInstances allows cross-DAG mutation
Rahul Vats
-
CVE-2026-41017: Apache Airflow: JWT cookie missing Secure flag in JWTRefreshMiddleware behind HTTPS-terminating proxy
Rahul Vats
-
CVE-2026-49267: Apache Airflow: No certificate validation on SMTP STARTTLS connections
Rahul Vats
-
CVE-2026-41014: Apache Airflow: per-DAG RBAC bypass on /ui/partitioned_dag_runs endpoints
Rahul Vats
-
CVE-2026-40963: Apache Airflow: DAG authorization bypass on /ui/structure/structure_data
Rahul Vats
-
CVE-2026-40961: Apache Airflow: Open Redirect Bypass Vulnerability
Rahul Vats
-
CVE-2026-40861: Apache Airflow: Arbitrary File Read via Log Symlink following in FileTaskHandler
Rahul Vats
-
[ANNOUNCE] Apache ActiveMQ 5.19.7 has been released!
Jean-Baptiste Onofré
-
[ANNOUNCE] Apache ActiveMQ 6.2.6 has been released!
Jean-Baptiste Onofré
-
CVE-2026-49361: Apache Fluss Netty Frame Decoder Memory Exhaustion Vulnerability
Jark Wu
-
[ANN] Apache Maven Daemon 1.0.6 released
Tamás Cservenák
-
[ANNOUNCE] Apache Fesod(Incubating) 2.0.2-incubating released
delei
-
CVE-2026-48827: Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git
Thomas Wolf
-
CVE-2026-44825: Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
Jan Høydahl
-
[ANN] Apache Struts 6.10.0
Lukasz Lenart
-
[ANNOUNCE] Apache Axis2/Java 2.0.1 Released
robertlazarski
-
[ANNOUNCE] Apache Axis2/C 2.0.0 Released
robertlazarski
-
[ANNOUNCEMENT] Commons Daemon 1.6.0 Released
Mark Thomas
-
[ANNOUNCE] Apache bRPC 1.17.0 released
Xiguo Hu
-
[ANNOUNCE] Apache MINA SSHD 3.0.0-M4 released
Thomas Wolf
-
[ANNOUNCE] Apache MINA SSHD 2.18.0 released
Thomas Wolf
-
[ANNOUNCE] Apache Airflow Providers prepared on 2026-05-25 are released
Jens Scheffler
-
ARTEMIS-5996: CVE-2026-40914: Apache Artemis, Apache ActiveMQ Artemis: Address routing-type can be updated by STOMP protocol user without the createAddress permission
Justin Bertram
-
[ANNOUNCE] Apache Commons Configuration 2.15.1
Gary Gregory
-
CVE-2026-40564: Apache Flink Kubernetes Operator: Server-Side Request Forgery and local file access in Kubernetes Operator
Gyula Fora
-
[ANNOUNCE] Apache Tika 3.3.1 released
Tim Allison
-
CVE-2026-48589: Apache Shiro: Jakarta EE open redirect via untrusted Referer in post-login redirect flow
Lenny Primak
-
CVE-2026-44598: Apache Shiro Jakarta EE module: Open redirect and SSRF (requires valid credentials)
Lenny Primak
-
CVE-2026-43828: Apache Shiro: Shiro's native session and rememberMe cookies do not have secure flag set by default
Lenny Primak
-
CVE-2026-43827: Apache Shiro: Session fixation: new session is not created after login by default
Lenny Primak
-
[ANN] Apache Syncope 4.0.6
Francesco Chicchiriccò
-
[ANN] Apache Syncope 4.1.1
Francesco Chicchiriccò
-
CVE-2026-42797: Apache Syncope: JexlContextBuilder Information Disclosure
Francesco Chicchiriccò
-
CVE-2026-42782: Apache Syncope: Post-auth RCE via Groovy static
Francesco Chicchiriccò
-
[ANNOUNCE] Apache Doris 4.1.1
Mingyu Chen
-
CVE-2026-46745: Apache Airflow FAB provider: [ Security Report ] LDAP Filter Injection in FAB Auth Manager _search_ldap reachable via /auth/token (ZDRES-223)
Jens Scheffler
-
CVE-2026-45361: Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)
Jens Scheffler
-
[ANNOUNCE] Apache Airflow Providers prepared on 2026-05-19 are released
Jens Scheffler
-
CVE-2026-45249: Apache ECharts: XSS in Lines series tooltip rendering
Zhongxiang Wang
-
[ANNOUNCE] Apache Kafka 4.3.0
Mickael Maison
-
CVE-2026-44930: Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository
Colm O hEigeartaigh
-
CVE-2026-44618: Apache CXF: XXE vulnerability in WS-Transfer functionality
Colm O hEigeartaigh
-
CVE-2026-44417: Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE)
Colm O hEigeartaigh
-
[ANNOUNCE] Apache Teaclave™ TrustZone SDK 0.9.0 Released
Zehui Chen
-
[ANNOUNCE] Apache Fory 1.0.0 released
Shawn Yang
-
[ANNOUNCE] Apache Pulsar Client Python 3.12.0 released
Yunze Xu
-
CVE-2026-48207: Apache Fory: PyFory ReduceSerializer Incomplete Policy Enforcement
Chaokun Yang
-
https://camel.apache.org/security/CVE-2026-45760.html: CVE-2026-45760: Apache Camel K: Camel K Cross-Namespace Build Deputy Attack
Pasquale Congiusti
-
[ANNOUNCE] Apache Wicket 10.9.1 released
Andrea Del Bene
-
[ANNOUNCE] Apache PDFBox JBIG2 ImageIO plugin 3.0.5 released
Andreas Lehmkühler
-
[ANNOUNCE] Apache NetBeans 30 Released
Eric Barboni
-
[ANNOUNCE] Apache Artemis 2.54.0 Released
Justin Bertram
-
CVE-2026-42526: Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
Vincent Beck
-
CVE-2026-27173: Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Arguments
Vincent Beck
-
[ANNOUNCE] Apache CouchDB 3.5.2 released
Jan Lehnardt
-
[ANNOUNCE] Apache OFBiz 24.09.06 released
Jacopo Cappellato
-
[ANNOUNCE] Apache Storm 2.8.8 Released
Rui Abreu
-
CVE-2026-47323: Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering
Andrea Cosentino
-
CVE-2026-31909: Apache OFBiz: Unauthenticated Shipment Label Image Disclosure
Jacopo Cappellato
-
CVE-2026-46586: Apache OFBiz: Improper Validation in traverseContent Service Enables Authenticated Groovy Code Execution
Jacopo Cappellato
-
CVE-2026-45434: Apache OFBiz: Authentication Bypass via Password-Change Logic Flaw Leading to RCE
Jacopo Cappellato
-
CVE-2026-45187: Apache OFBiz: Improper Authorization in Scheduled Job Creation Allows Low-Privileged Users to Submit System Jobs
Jacopo Cappellato
-
CVE-2026-41919: Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Construction
Jacopo Cappellato
-
CVE-2026-35086: Apache OFBiz: Authenticated Remote Code Execution via Unsafe Template Expansion in email services
Jacopo Cappellato
-
CVE-2026-31910: Apache OFBiz: Improper Input Validation in UI Factory Classes Leads to SSRF and Blind File Access
Jacopo Cappellato
-
CVE-2026-31986: Apache OFBiz: Unauthenticated RCE via Default JWT Signing Key and Widget Template Injection
Jacopo Cappellato
-
CVE-2026-31388: Apache OFBiz: Cross-Tenant Data Exposure via Program Export Feature
Jacopo Cappellato
-
CVE-2026-31380: Apache OFBiz: FreeMarker SSTI via Duplicate Parameter Sanitization Bypass
Jacopo Cappellato
-
CVE-2026-31906: Apache OFBiz: Reflected XSS via Improper HTML Attribute Escaping in Layered-Modal Dialog Parameters
Jacopo Cappellato
-
CVE-2026-31379: Apache OFBiz: Path Traversal and File Upload Validation Bypass Leading to Arbitrary File Write, Stored XSS and RCE in Catalog Manager
Jacopo Cappellato
-
CVE-2026-31387: Apache OFBiz: Cookie Manipulation Allows Authenticated JWT Forgery and Account Impersonation
Jacopo Cappellato
-
CVE-2026-31378: Apache OFBiz: JSON Attribute Override and URL Allowlist Bypass Leads to Remote Code Execution
Jacopo Cappellato
-
CVE-2026-29226: Apache OFBiz: Low-Privilege SSRF in Content Component
Jacopo Cappellato
-
CVE-2026-29220: Apache OFBiz: Low-Privilege LFI in Content Component
Jacopo Cappellato
-
CVE-2026-29207: Apache OFBiz: Low-Privilege SSTI Leading to RCE in the Content Component
Jacopo Cappellato
-
[ANN] Apache Maven Enforcer Plugin 3.6.3 Released
Tamás Cservenák
-
[ANN] Maven Resolver 2.0.18 released
Tamás Cservenák
-
[ANN] Apache Maven 3.9.16 released
Slawomir Jaranowski
-
[ANNOUNCE] Apache Flink 2.2.1 released
Sergey Nuyanzin
-
[ANNOUNCE] Apache Wicket 8.18.0 released
Andrea Del Bene
-
CVE-2026-35194: Apache Flink: Remote code execution via SQL injection in code generation
Martijn Visser
-
CVE-2026-45205: Apache Commons Configuration: StackOverflowError for YAML input with cycles
Gary D. Gregory
-
[ANNOUNCE] Apache Commons Configuration 2.15.0
Gary Gregory
-
[ANNOUNCE] Apache Wicket 9.23.0 released
Andrea Del Bene
-
[SECURITY] CVE-2026-43515 Apache Tomcat - Security constraints not correctly applied
Mark Thomas
-
[SECURITY] CVE-2026-43513 Apache Tomcat - LockOutRealm treats user names as case-sensitive
Mark Thomas
-
[SECURITY] CVE-2026-43514 Apache Tomcat - AJP secret compared in non-constant time
Mark Thomas
-
[SECURITY] CVE-2026-43512 Apache Tomcat - Digest authenticator will authenticate any unknown user
Mark Thomas
-
[SECURITY] CVE-2026-42498 Apache Tomcat - WebSocket authentication header exposure
Mark Thomas
-
[SECURITY] CVE-2026-41293 Apache Tomcat - HTTP/2 request headers not validated
Mark Thomas
-
[SECURITY] CVE-2026-41284 Apache Tomcat - Unbounded read in WebDAV LOCK and PROPFIND handling
Mark Thomas
-
[ANNOUNCE] Apache Burr 0.42.0-incubating released
Elijah ben Izzy
-
[ANNOUNCE] Apache Parquet Java 1.17.1
Gang Wu
-
[ANNOUNCE] Apache Calcite Avatica 1.28.0 Released
Francis Chuang
-
[ANN] Apache Tomcat 10.1.55 Available
Christopher Schultz
-
[ANNOUNCE] Apache Airflow Providers prepared on 2026-05-05 are released
Vincent Beck
-
[ANNOUNCE] Apache Tika 4.0.0-alpha-1 released
Tim Allison
-
[ANN] Apache Tomcat 9.0.118 available
Rémy Maucherat
-
CVE-2026-41018: Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak credentials embedded in the host URL
Shahar Epstein
-
CVE-2026-43826: Apache Airflow Providers OpenSearch: OpenSearch task-log handler leaks credentials embedded in the host URL
Shahar Epstein
-
[ANNOUNCE] Apache Grails Spring Security 8.0.0-M1
Mattias Reichel
-
[ADVISORY] Apache CloudStack LTS Security Releases 4.20.3.0 and 4.22.0.1
Daan Hoogland
-
[ANNOUNCE] Release Apache Paimon Rust 0.1.0
yuxia luo
-
[ANNOUNCE] Apache Grails 8.0.0-M1
James Fredley
-
[ANNOUNCE] Apache Pulsar C# Client DotPulsar 5.3.1 released
David Jensen
-
[ANNOUNCE] Apache Groovy 6.0.0-alpha-1 Released
Paul King
-
[ANNOUNCE] Apache Groovy 4.0.32 Released
Paul King
-
[ANNOUNCE] Apache Groovy 5.0.6 Released
Paul King
-
[ANNOUNCE] Apache Ignite 2.18.0 Released
zstan
-
[ANNOUNCE] SkyWalking Helm Chart 4.9.0 released
han liu
-
[ANNOUNCE] Apache Wicket 10.9.0 released
Andrea Del Bene
-
[ANNOUNCE] Apache Airflow CTL 0.1.4 from 0.1.4rc3 released
Jarek Potiuk
-
CVE-2026-43975: Apache Wicket: Possible malicious path traversal in FolderUploadsFileManager
Pedro Henrique Oliveira dos Santos
-
CVE-2026-43646: Apache Wicket: crafted URLs can bypass PackageResourceGuard
Pedro Henrique Oliveira dos Santos
-
CVE-2026-42509: Apache Wicket: crafted strings can break out of the JavaScript sequence
Pedro Henrique Oliveira dos Santos
-
CVE-2026-40010: Apache Wicket: possible session fixation using AuthenticatedWebSession
Pedro Henrique Oliveira dos Santos
-
CVE-2026-28780: Apache HTTP Server: buffer overflow in mod_proxy_ajp via ajp_msg_check_header()
Eric Covener
-
[ANN] Apache Tomcat 11.0.22 Available
Mark Thomas
-
[ANNOUNCE] Apache Commons Statistics 1.3 Released
Alex Herbert
-
[ANNOUNCE] Apache TomEE 10.1.5
Markus Jung
-
[ANNOUNCE] Apache Atlas 2.5.0 released
Madhan Neethiraj
-
CVE-2026-29168: Apache HTTP Server: mod_md unrestricted OCSP response
Eric Covener
-
CVE-2026-43869: Apache Thrift: TSSLTransportFactory.java hostname verification
Jens Geyer
-
CVE-2026-43870: Apache Thrift: Node.js web_server.js multi-vulnerability
Jens Geyer
-
CVE-2026-43868: Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern
Jens Geyer
-
CVE-2026-33523: Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line
Eric Covener
-
CVE-2026-33007: Apache HTTP Server: mod_authn_socache crash
Eric Covener
-
CVE-2026-33006: Apache HTTP Server: mod_auth_digest timing attack
Eric Covener
-
CVE-2026-29169: Apache HTTP Server: mod_dav_lock indirect lock crash
Eric Covener
-
CVE-2026-23918: Apache HTTP Server: http2: double free and possible RCE on early reset
Eric Covener
-
CVE-2026-24072: Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr
Eric Covener
-
[ANNOUNCEMENT] Apache HTTP Server 2.4.67 Released
covener
-
[ANNOUNCE] Grails Publish Gradle Plugin 1.0.0-M1
James Daugherty
-
[ANNOUNCE] Apache Grails 7.1.1
James Daugherty
-
[ANNOUNCE] Apache Pekko (Core) 1.6.0 released
PJ Fanning
-
[ANNOUNCE] Apache Grails 7.0.11
James Daugherty
-
[ANNOUNCE] Apache Grails Spring Security 7.0.2
James Daugherty
-
[ANNOUNCE] Grails Publish Gradle Plugin 0.0.5
James Daugherty
-
[ANNOUNCE] Apache Grails GitHub Actions 1.0.2
James Daugherty
-
CVE-2026-34059: Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data()
Eric Covener
-
CVE-2026-34032: Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)
Eric Covener
-
CVE-2026-33857: Apache HTTP Server: Off-by-one OOB reads in AJP getter functions
Eric Covener
-
CVE-2026-40563: Apache Atlas: Script injection allows access to unintended data
Pinal Shah
-
[ANNOUNCE] Apache Polaris 1.4.1
Jean-Baptiste Onofré
-
[ANNOUNCE] OpenNLP 2.5.9 released
Richard Zowalla
-
[ANNOUNCE] OpenNLP 3.0.0-M3 released
Richard Zowalla
-
CVE-2026-42812: Apache Polaris: No protection on `write.metadata.path`
Jean-Baptiste Onofré
-
CVE-2026-42811: Apache Polaris: In plain terms, Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across the configured bucket instead.
Jean-Baptiste Onofré
-
CVE-2026-42810: Apache Polaris: Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters appear to be reused unescaped in S3 IAM resource patterns and `s3:prefix` conditions.
Jean-Baptiste Onofré
-
CVE-2026-42809: Apache Polaris: An authenticated low-privileged user can abuse Polaris staged table creation to mint broad temporary storage credentials for an attacker-chosen location before Polaris validates that location
Jean-Baptiste Onofré
-
CVE-2026-42440: Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader
Richard Zowalla
-
CVE-2026-42027: Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader
Richard Zowalla
-
CVE-2026-40682: Apache OpenNLP: XXE via Dictionary Parsing in DictionaryEntryPersistor
Richard Zowalla
-
CVE-2026-42404: Apache Neethi: Unrestricted HTTP Redirect Following in Policy References
Colm O hEigeartaigh
-
CVE-2026-42402: Apache Neethi: Policy Normalization Unbounded Resource Allocation DoS
Colm O hEigeartaigh
-
[ANNOUNCE] Release Apache OpenDAL 0.56.0
Xuanwo
-
CVE-2026-42403: Apache Neethi: Circular Policy Reference Infinite Loop
Colm O hEigeartaigh
-
Apache MINA 2.0.12 and 2.2.7 release
Emmanuel Lecharny
-
[ANNOUNCE] Apache Pulsar Helm Chart version 4.6.0 Released
Lari Hotari
-
Apache Beam 2.73.0 Released!
Vitalii Terentev
-
[ANNOUNCE] Apache James MIME4J 0.8.14 released
[email protected]
-
[ANNOUNCE] Apache Accumulo Access 1.0.0-beta3
Christopher
-
[ANNOUNCE] Apache KIE (Incubating) 10.2.0 released
Alex Porcelli
-
Re: CVE-2026-41016: Apache Airflow SMTP Provider: No certificate validation on SMTP STARTTLS connections
Shahar Epstein
-
Apache MINA 2.0.28, 2.0.11 and 2.2.6 release
Emmanuel Lecharny
-
ANNOUNCE] Apache Jackrabbit Oak 1.22.24 released
Julian Reschke
-
CVE-2026-41873: Pony Mail: Admin account takeover via request smuggling
Arnout Engelen
-
[ANN] Apache Struts 6.9.0
Lukasz Lenart