
security-research — Actualizado!
Vulnerabilidades que he reportado a la Apache Software Foundation: 46 CVE en 15 proyectos
Investigación de Seguridad
Vulnerabilidades que he reportado a la Apache Software Foundation, divulgadas a través del proceso de seguridad de la ASF. 46 CVE en 15 proyectos, de 2023 a 2026.
Cuando existe un reproductor público, se enlaza. Cada uno es un proyecto mínimo y autocontenido que demuestra el problema e indica la versión que lo corrigió.
A lo largo de 25 CWE distintos, dos clases dominan: deserialización de datos no confiables (7) y server-side request forgery (7).
En todo el ecosistema Apache: 16 CVE, 14 proyectos
| CVE | Componente | Clase | Corregido en | PoC |
|---|---|---|---|---|
| CVE-2023-41313 | Doris | CWE-208 Observable Timing Discrepancy | 1.2.8 | - |
| CVE-2023-41834 | Flink Stateful Functions | CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component | 3.3.0 | - |
| CVE-2023-43123 | Storm | CWE-200 Exposure of Sensitive Information to an Unauthorized Actor | 2.6.0 | - |
| CVE-2024-23454 | Hadoop | CWE-378 Creation of Temporary File With Insecure Permissions | 3.4.0 | - |
| CVE-2024-23953 | Hive | CWE-208 Observable Timing Discrepancy | 4.0.0 | - |
| CVE-2024-29869 | Hive | CWE-732 Incorrect Permission Assignment for Critical Resource | 4.0.1 | - |
| CVE-2026-28672 | Ranger | CWE-77 Improper Neutralization of Special Elements used in a Command | 2.9.0 | reproductor |
| CVE-2026-34476 | SkyWalking MCP | CWE-918 Server-Side Request Forgery | no publicado | - |
| CVE-2026-40005 | IoTDB | CWE-22 Improper Limitation of a Pathname to a Restricted Directory | 2.0.10 | - |
| CVE-2026-40008 | IoTDB | CWE-470 Use of Externally-Controlled Input to Select Classes or Code | 2.0.10 | - |
| CVE-2026-40564 | Flink Kubernetes Operator | CWE-918 Server-Side Request Forgery | 1.15.0 | reproductor |
| CVE-2026-41041 | Gravitino | CWE-177 Improper Handling of URL Encoding | 1.2.1 | - |
| CVE-2026-44616 | Zeppelin | CWE-90 Improper Neutralization of Special Elements used in an LDAP Query | 0.12.1 | - |
| CVE-2026-49361 | Fluss (incubating) | CWE-400 Uncontrolled Resource Consumption | no publicado | - |
| CVE-2026-63039 | InLong | CWE-89 Improper Neutralization of Special Elements used in an SQL Command | 2.4.0 | reproductor |
| CVE-2026-64640 | Polaris | CWE-863 Incorrect Authorization | 1.7.0 | reproductor |
Apache Camel: 30 CVE
Camel es el proyecto que mantengo, por lo que recibe el mayor escrutinio. El patrón dominante es encabezados entrantes sin filtrar que llegan al plano de control de un productor, además de una larga cola de deserialización insegura en rutas de registro y migración.
| CVE | Componente | Clase | Corregido en | PoC |
|---|---|---|---|---|
| CVE-2024-23114 | Camel | CWE-502 Deserialization of Untrusted Data | 3.21.4, 3.22.1, 4.0.4, 4.4.0 | - |
| CVE-2026-23552 | Camel | CWE-346 Origin Validation Error | 4.18.0 | reproductor |
| CVE-2026-25747 | Camel LevelDB | CWE-502 Deserialization of Untrusted Data | 4.10.9, 4.14.5, 4.18.0 | reproductor |
| CVE-2026-27172 | Camel | CWE-502 Deserialization of Untrusted Data | 4.14.6, 4.18.1 | reproductor |
| CVE-2026-40047 | Camel | CWE-88 Improper Neutralization of Argument Delimiters in a Command | 4.18.3 | reproductor |
| CVE-2026-40048 | Camel PQC | CWE-502 Deserialization of Untrusted Data | 4.18.2, 4.20.0 | reproductor |
| CVE-2026-43866 | Camel | CWE-502 Deserialization of Untrusted Data | 4.14.8, 4.18.3, 4.21.0 | reproductor |
| CVE-2026-43867 | Camel | CWE-502 Deserialization of Untrusted Data | 4.18.3, 4.21.0 | reproductor |
| CVE-2026-46455 | Camel | CWE-613 Insufficient Session Expiration | 4.18.3, 4.21.0 | reproductor |
| CVE-2026-46585 | Camel Lucene | CWE-639 Authorization Bypass Through User-Controlled Key | 4.14.8, 4.18.3, 4.21.0 | reproductor |
| CVE-2026-46590 | Camel | CWE-502 Deserialization of Untrusted Data | 4.18.3, 4.21.0 | reproductor |
| CVE-2026-46591 | Camel | CWE-943 Improper Neutralization of Special Elements in Data Query Logic | 4.14.8, 4.18.3, 4.21.0 | reproductor |
| CVE-2026-46592 | Camel | CWE-441 Unintended Proxy or Intermediary | 4.14.8, 4.18.3, 4.21.0 | reproductor |
| CVE-2026-46726 | Camel Vertx Websocket | CWE-918 Server-Side Request Forgery | 4.14.8, 4.18.3, 4.21.0 | reproductor |
| CVE-2026-48203 | Camel | CWE-918 Server-Side Request Forgery | 4.14.8, 4.18.3, 4.21.0 | reproductor |
| CVE-2026-48204 | Camel | CWE-284 Improper Access Control | 4.14.8, 4.18.3, 4.21.0 | reproductor |
| CVE-2026-48205 | Camel DNS | CWE-918 Server-Side Request Forgery | 4.14.8, 4.18.3, 4.21.0 | reproductor |
| CVE-2026-48206 | Camel JIRA | CWE-639 Authorization Bypass Through User-Controlled Key | 4.14.8, 4.18.3, 4.21.0 | reproductor |
| CVE-2026-49086 | Camel Dapr | CWE-441 Unintended Proxy or Intermediary | 4.14.8, 4.18.3, 4.21.0 | reproductor |
| CVE-2026-49097 | Camel | CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component | 4.14.8, 4.18.3, 4.21.0 | reproductor |
| CVE-2026-49098 | Camel | CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component | 4.14.8, 4.18.3, 4.21.0 | reproductor |
| CVE-2026-49099 | Camel Salesforce | CWE-639 Authorization Bypass Through User-Controlled Key | 4.14.8, 4.18.3, 4.21.0 | reproductor |
| CVE-2026-49365 | Camel | CWE-209 Generation of Error Message Containing Sensitive Information | 4.14.8, 4.18.3, 4.21.0 | reproductor |
| CVE-2026-53913 | Camel Keycloak | CWE-636 Not Failing Securely | 4.18.3, 4.21.0 | reproductor |
| CVE-2026-55993 | Camel Atmosphere Websocket | CWE-918 Server-Side Request Forgery | 4.14.8, 4.18.3, 4.21.0 | reproductor |
| CVE-2026-55994 | Camel Iggy | CWE-918 Server-Side Request Forgery | 4.18.3, 4.21.0 | reproductor |
| CVE-2026-56139 | Camel Undertow | CWE-209 Generation of Error Message Containing Sensitive Information | 4.14.8, 4.18.3, 4.21.0 | reproductor |
| CVE-2026-56140 | Camel AWS2 SNS | CWE-20 Improper Input Validation | 4.14.8, 4.18.3, 4.21.0 | - |
| CVE-2026-63621 | Camel Knative | CWE-20 Improper Input Validation | 4.14.9, 4.18.4, 4.22.0 | reproductor |
| CVE-2026-78329 | Camel Undertow | CWE-20 Improper Input Validation | 4.14.9, 4.18.4, 4.22.0 | reproductor |
Reproductores para problemas encontrados por otros: 26
Como mantenedor de Camel, también creo reproductores para los informes que llegan desde fuera, con el fin de confirmar el problema y validar la corrección. Estos no son mis hallazgos. El crédito corresponde a los reportantes nombrados a continuación.
| CVE | Componente | Clase | Corregido en | Reportado por | PoC |
|---|---|---|---|---|---|
| CVE-2024-22369 | Camel | CWE-502 Deserialization of Untrusted Data | 3.21.4, 3.22.1, 4.0.4, 4.4.0 | Ziyang Chen from HuaWei Open Source Management Center, Pingtao Wei from HuaWei Open Source Management Center (finder) and Haoran Zhi from HuaWei Open Source Management Center | reproductor |
| CVE-2026-33453 | Camel | CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes | 4.18.1, 4.19.0 | Hyunwoo Kim (@v4bel) | reproductor |
| CVE-2026-33454 | Camel | CWE-502 Deserialization of Untrusted Data | 4.14.6, 4.18.1 | Hyunwoo Kim (@v4bel) | reproductor |
| CVE-2026-40022 | Camel Platform HTTP Main | CWE-288 Authentication Bypass Using an Alternate Path or Channel | 4.14.6, 4.18.2 | Jihang Yu | reproductor |
| CVE-2026-40453 | Camel JMS | CWE-178 Improper Handling of Case Sensitivity | 4.14.6, 4.18.2, 4.20.0 | Saroj Khadka | reproductor |
| CVE-2026-40473 | Camel Mina | CWE-502 Deserialization of Untrusted Data | 4.14.6, 4.18.2, 4.20.0 | Venkatraman Kumar from Securin | reproductor |
| CVE-2026-40858 | Camel | CWE-502 Deserialization of Untrusted Data | 4.14.7, 4.18.2, 4.20.0 | Feng Ning from Innora Pte. Ltd. | reproductor |
| CVE-2026-40859 | Camel | CWE-502 Deserialization of Untrusted Data | 4.14.8, 4.18.3, 4.20.0 | Venkatraman Kumar from Securin | reproductor |
| CVE-2026-40860 | Camel | CWE-502 Deserialization of Untrusted Data | 4.14.7, 4.18.2, 4.20.0 | Venkatraman Kumar from Securin | reproductor |
| CVE-2026-42527 | Camel | CWE-502 Deserialization of Untrusted Data | 4.14.8, 4.18.3, 4.21.0 | Venkatraman Kumar from Securin and Yu Bao from Paypal | reproductor |
| CVE-2026-43865 | Camel | CWE-502 Deserialization of Untrusted Data | 4.14.8, 4.18.3, 4.21.0 | gaorenyusi | reproductor |
| CVE-2026-46453 | Camel | CWE-639 Authorization Bypass Through User-Controlled Key | 4.14.8, 4.18.3, 4.21.0 | Yu Bao from PayPal | reproductor |
| CVE-2026-46454 | Camel | CWE-20 Improper Input Validation | 4.14.8, 4.18.3, 4.21.0 | Yu Bao from PayPal | reproductor |
| CVE-2026-46456 | Camel | CWE-20 Improper Input Validation | 4.14.8, 4.18.3, 4.21.0 | Yu Bao from PayPal | reproductor |
| CVE-2026-46457 | Camel | CWE-20 Improper Input Validation | 4.14.8, 4.18.3, 4.21.0 | Yu Bao from PayPal | reproductor |
| CVE-2026-46584 | Camel Mail | CWE-200 Exposure of Sensitive Information to an Unauthorized Actor | 4.14.8, 4.18.3, r | Yu Bao from PayPal | reproductor |
| CVE-2026-46587 | Camel | CWE-20 Improper Input Validation | 4.14.8, 4.18.3, 4.21.0 | Yu Bao from PayPal | reproductor |
| CVE-2026-46588 | Camel | CWE-20 Improper Input Validation | 4.14.8, 4.18.3, 4.21.0 | Yu Bao from PayPal | reproductor |
| CVE-2026-47323 | Camel | CWE-178 Improper Handling of Case Sensitivity | 4.14.6, 4.18.2 | Quac Tran | reproductor |
| CVE-2026-49042 | Camel | CWE-20 Improper Input Validation | 4.18.3, 4.21.0 | Yu Bao from PayPal | reproductor |
| CVE-2026-59230 | Camel Mail | CWE-20 Improper Input Validation | 4.14.9, 4.18.4, 4.22.0 | Atuin - Automated Vulnerability Discovery Engine, anciety of Tencent Xuanwu Lab | reproductor |
| CVE-2026-60093 | Camel Azure Storage Datalake | CWE-22 Improper Limitation of a Pathname to a Restricted Directory | 4.14.9, 4.18.4, 4.22.0 | n0mi1k and Hiep Nguyen | reproductor |
| CVE-2026-66906 | Camel Azure Storage Blob | CWE-22 Improper Limitation of a Pathname to a Restricted Directory | 4.14.9, 4.18.4, 4.22.0 | n0mi1k and Hiep Nguyen | reproductor |
| CVE-2026-66907 | Camel Google Storage | CWE-22 Improper Limitation of a Pathname to a Restricted Directory | 4.14.9, 4.18.4, 4.22.0 | n0mi1k | reproductor |
| CVE-2026-66908 | Camel Platform HTTP Main | CWE-287 Improper Authentication | 4.22.0 | n0mi1k | reproductor |
| CVE-2026-71300 | Camel Atmosphere Websocket | CWE-20 Improper Input Validation | 4.14.9, 4.18.4, 4.22.0 | Barak Srour from Apiiro | reproductor |
Los hallazgos se reportan de forma privada al equipo de seguridad de la ASF correspondiente y se publican solo después de que se lanza una corrección. Los reproductores apuntan a la versión vulnerable y están destinados a defensores que validan su propia exposición.