Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
security-research — Vulnerabilities I've reported to the Apache Software Foundation: 46 CVEs across 15 projects | Kitploit
Tools/GitHubGitHub/oscerd/security-research
Vulnerability AnalysisExploitationWeb SecurityCurated Resources
GitHuboscerd/security-research

security-research

Vulnerabilities I've reported to the Apache Software Foundation: 46 CVEs across 15 projects

View Repository
1208 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Security Research

Vulnerabilities I have reported to the Apache Software Foundation, disclosed through the ASF security process. 46 CVEs across 15 projects, 2023 to 2026.

Where a public reproducer exists it is linked. Each one is a minimal, self-contained project that demonstrates the issue and names the release that fixed it.

Across 25 distinct CWEs, two classes dominate: deserialization of untrusted data (7) and server-side request forgery (7).

Across the Apache ecosystem: 16 CVEs, 14 projects

CVEComponentClassFixed inPoC
CVE-2023-41313DorisCWE-208 Observable Timing Discrepancy1.2.8-
CVE-2023-41834Flink Stateful FunctionsCWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component3.3.0-
CVE-2023-43123StormCWE-200 Exposure of Sensitive Information to an Unauthorized Actor2.6.0-
CVE-2024-23454HadoopCWE-378 Creation of Temporary File With Insecure Permissions3.4.0-
CVE-2024-23953HiveCWE-208 Observable Timing Discrepancy4.0.0-
CVE-2024-29869HiveCWE-732 Incorrect Permission Assignment for Critical Resource4.0.1-
CVE-2026-28672RangerCWE-77 Improper Neutralization of Special Elements used in a Command2.9.0reproducer
CVE-2026-34476SkyWalking MCPCWE-918 Server-Side Request Forgerynot published-
CVE-2026-40005IoTDBCWE-22 Improper Limitation of a Pathname to a Restricted Directory2.0.10-
CVE-2026-40008IoTDBCWE-470 Use of Externally-Controlled Input to Select Classes or Code2.0.10-
CVE-2026-40564Flink Kubernetes OperatorCWE-918 Server-Side Request Forgery1.15.0reproducer
CVE-2026-41041GravitinoCWE-177 Improper Handling of URL Encoding1.2.1-
CVE-2026-44616ZeppelinCWE-90 Improper Neutralization of Special Elements used in an LDAP Query0.12.1-
CVE-2026-49361Fluss (incubating)CWE-400 Uncontrolled Resource Consumptionnot published-
CVE-2026-63039InLongCWE-89 Improper Neutralization of Special Elements used in an SQL Command2.4.0reproducer
CVE-2026-64640PolarisCWE-863 Incorrect Authorization1.7.0reproducer

Apache Camel: 30 CVEs

Camel is the project I maintain, so it gets the most scrutiny. The dominant pattern is unfiltered inbound headers reaching a producer's control plane, plus a long tail of unsafe deserialization in registry and migration paths.

Download Tool