Skip to content
KitploitKITPLOIT
OutilsBlog
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
security-research — Vulnérabilités que j'ai signalées à l'Apache Software Foundation : 46 CVE réparties sur 15 projets | Kitploit
Outils/GitHubGitHub/oscerd/security-research
Analyse des VulnérabilitésExploitationSécurité WebRessources Organisées
GitHuboscerd/security-research

security-research

Vulnérabilités que j'ai signalées à l'Apache Software Foundation : 46 CVE réparties sur 15 projets

Voir le dépôt
5il y a 18 joursPas encore vérifié

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager

Recherche de sécurité

Vulnérabilités que j'ai signalées à l'Apache Software Foundation, divulguées via le processus de sécurité de l'ASF. 46 CVE sur 15 projets, de 2023 à 2026.

Lorsqu'un reproducteur public existe, il est lié. Chacun est un projet minimal et autonome qui démontre le problème et indique la version qui l'a corrigé.

À travers 25 CWE distincts, deux classes dominent : la désérialisation de données non fiables (7) et la falsification de requête côté serveur (7).

À travers l'écosystème Apache : 16 CVE, 14 projets

CVEComposantClasseCorrigé dansPoC
CVE-2023-41313DorisCWE-208 Observable Timing Discrepancy1.2.8-
CVE-2023-41834Flink Stateful FunctionsCWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component3.3.0-
CVE-2023-43123StormCWE-200 Exposure of Sensitive Information to an Unauthorized Actor2.6.0-
CVE-2024-23454HadoopCWE-378 Creation of Temporary File With Insecure Permissions3.4.0-
CVE-2024-23953HiveCWE-208 Observable Timing Discrepancy4.0.0-
CVE-2024-29869HiveCWE-732 Incorrect Permission Assignment for Critical Resource4.0.1-
CVE-2026-28672RangerCWE-77 Improper Neutralization of Special Elements used in a Command2.9.0reproducteur
CVE-2026-34476SkyWalking MCPCWE-918 Server-Side Request Forgerynon publié-
CVE-2026-40005IoTDBCWE-22 Improper Limitation of a Pathname to a Restricted Directory2.0.10-
CVE-2026-40008IoTDBCWE-470 Use of Externally-Controlled Input to Select Classes or Code2.0.10-
CVE-2026-40564Flink Kubernetes OperatorCWE-918 Server-Side Request Forgery1.15.0reproducteur
CVE-2026-41041GravitinoCWE-177 Improper Handling of URL Encoding1.2.1-
CVE-2026-44616ZeppelinCWE-90 Improper Neutralization of Special Elements used in an LDAP Query0.12.1-
CVE-2026-49361Fluss (incubating)CWE-400 Uncontrolled Resource Consumptionnon publié-
CVE-2026-63039InLongCWE-89 Improper Neutralization of Special Elements used in an SQL Command2.4.0reproducteur
CVE-2026-64640PolarisCWE-863 Incorrect Authorization1.7.0reproducteur

Apache Camel : 30 CVE

Camel est le projet que je maintiens, il est donc le plus scruté. Le schéma dominant est des en-têtes entrants non filtrés atteignant le plan de contrôle d'un producteur, plus une longue traîne de désérialisation non sécurisée dans les chemins de registre et de migration.

CVEComposantClasseCorrigé dansPoC
CVE-2024-23114CamelCWE-502 Deserialization of Untrusted Data3.21.4, 3.22.1, 4.0.4, 4.4.0-
CVE-2026-23552CamelCWE-346 Origin Validation Error4.18.0reproducteur
CVE-2026-25747Camel LevelDBCWE-502 Deserialization of Untrusted Data4.10.9, 4.14.5, 4.18.0reproducteur
CVE-2026-27172CamelCWE-502 Deserialization of Untrusted Data4.14.6, 4.18.1reproducteur
CVE-2026-40047CamelCWE-88 Improper Neutralization of Argument Delimiters in a Command4.18.3reproducteur
CVE-2026-40048Camel PQCCWE-502 Deserialization of Untrusted Data4.18.2, 4.20.0reproducteur
CVE-2026-43866Camel Deserialization of Untrusted Data

Reproducteurs pour des problèmes trouvés par d'autres : 26

En tant que mainteneur de Camel, je construis aussi des reproducteurs pour les rapports qui viennent de l'extérieur, afin de confirmer le problème et de valider le correctif. Ce ne sont pas mes découvertes. Le crédit revient aux rapporteurs nommés ci-dessous.

CVEComposantClasseCorrigé dansRapporté parPoC
CVE-2024-22369CamelCWE-502 Deserialization of Untrusted Data3.21.4, 3.22.1, 4.0.4, 4.4.0Ziyang Chen from HuaWei Open Source Management Center, Pingtao Wei from HuaWei Open Source Management Center (finder) and Haoran Zhi from HuaWei Open Source Management Centerreproducteur
CVE-2026-33453CamelCWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes4.18.1, 4.19.0Hyunwoo Kim (@v4bel)reproducteur
CVE-2026-33454CamelCWE-502 Deserialization of Untrusted Data4.14.6, 4.18.1Hyunwoo Kim (@v4bel)reproducteur
CVE-2026-40022Camel Platform HTTP MainCWE-288 Authentication Bypass Using an Alternate Path or Channel4.14.6, 4.18.2Jihang Yureproducteur
CVE-2026-40453Camel JMSCWE-178 Improper Handling of Case Sensitivity4.14.6, 4.18.2, 4.20.0Saroj Khadkareproducteur
CVE-2026-40473

Les découvertes sont signalées en privé à l'équipe de sécurité ASF concernée et publiées uniquement après la sortie d'un correctif. Les reproducteurs ciblent la version vulnérable et sont destinés aux défenseurs validant leur propre exposition.

Télécharger l’outil
CWE-502
4.14.8, 4.18.3, 4.21.0
reproducteur
CVE-2026-43867CamelCWE-502 Deserialization of Untrusted Data4.18.3, 4.21.0reproducteur
CVE-2026-46455CamelCWE-613 Insufficient Session Expiration4.18.3, 4.21.0reproducteur
CVE-2026-46585Camel LuceneCWE-639 Authorization Bypass Through User-Controlled Key4.14.8, 4.18.3, 4.21.0reproducteur
CVE-2026-46590CamelCWE-502 Deserialization of Untrusted Data4.18.3, 4.21.0reproducteur
CVE-2026-46591CamelCWE-943 Improper Neutralization of Special Elements in Data Query Logic4.14.8, 4.18.3, 4.21.0reproducteur
CVE-2026-46592CamelCWE-441 Unintended Proxy or Intermediary4.14.8, 4.18.3, 4.21.0reproducteur
CVE-2026-46726Camel Vertx WebsocketCWE-918 Server-Side Request Forgery4.14.8, 4.18.3, 4.21.0reproducteur
CVE-2026-48203CamelCWE-918 Server-Side Request Forgery4.14.8, 4.18.3, 4.21.0reproducteur
CVE-2026-48204CamelCWE-284 Improper Access Control4.14.8, 4.18.3, 4.21.0reproducteur
CVE-2026-48205Camel DNSCWE-918 Server-Side Request Forgery4.14.8, 4.18.3, 4.21.0reproducteur
CVE-2026-48206Camel JIRACWE-639 Authorization Bypass Through User-Controlled Key4.14.8, 4.18.3, 4.21.0reproducteur
CVE-2026-49086Camel DaprCWE-441 Unintended Proxy or Intermediary4.14.8, 4.18.3, 4.21.0reproducteur
CVE-2026-49097CamelCWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component4.14.8, 4.18.3, 4.21.0reproducteur
CVE-2026-49098CamelCWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component4.14.8, 4.18.3, 4.21.0reproducteur
CVE-2026-49099Camel SalesforceCWE-639 Authorization Bypass Through User-Controlled Key4.14.8, 4.18.3, 4.21.0reproducteur
CVE-2026-49365CamelCWE-209 Generation of Error Message Containing Sensitive Information4.14.8, 4.18.3, 4.21.0reproducteur
CVE-2026-53913Camel KeycloakCWE-636 Not Failing Securely4.18.3, 4.21.0reproducteur
CVE-2026-55993Camel Atmosphere WebsocketCWE-918 Server-Side Request Forgery4.14.8, 4.18.3, 4.21.0reproducteur
CVE-2026-55994Camel IggyCWE-918 Server-Side Request Forgery4.18.3, 4.21.0reproducteur
CVE-2026-56139Camel UndertowCWE-209 Generation of Error Message Containing Sensitive Information4.14.8, 4.18.3, 4.21.0reproducteur
CVE-2026-56140Camel AWS2 SNSCWE-20 Improper Input Validation4.14.8, 4.18.3, 4.21.0-
CVE-2026-63621Camel KnativeCWE-20 Improper Input Validation4.14.9, 4.18.4, 4.22.0reproducteur
CVE-2026-78329Camel UndertowCWE-20 Improper Input Validation4.14.9, 4.18.4, 4.22.0reproducteur
Camel Mina
CWE-502 Deserialization of Untrusted Data
4.14.6, 4.18.2, 4.20.0
Venkatraman Kumar from Securin
reproducteur
CVE-2026-40858CamelCWE-502 Deserialization of Untrusted Data4.14.7, 4.18.2, 4.20.0Feng Ning from Innora Pte. Ltd.reproducteur
CVE-2026-40859CamelCWE-502 Deserialization of Untrusted Data4.14.8, 4.18.3, 4.20.0Venkatraman Kumar from Securinreproducteur
CVE-2026-40860CamelCWE-502 Deserialization of Untrusted Data4.14.7, 4.18.2, 4.20.0Venkatraman Kumar from Securinreproducteur
CVE-2026-42527CamelCWE-502 Deserialization of Untrusted Data4.14.8, 4.18.3, 4.21.0Venkatraman Kumar from Securin and Yu Bao from Paypalreproducteur
CVE-2026-43865CamelCWE-502 Deserialization of Untrusted Data4.14.8, 4.18.3, 4.21.0gaorenyusireproducteur
CVE-2026-46453CamelCWE-639 Authorization Bypass Through User-Controlled Key4.14.8, 4.18.3, 4.21.0Yu Bao from PayPalreproducteur
CVE-2026-46454CamelCWE-20 Improper Input Validation4.14.8, 4.18.3, 4.21.0Yu Bao from PayPalreproducteur
CVE-2026-46456CamelCWE-20 Improper Input Validation4.14.8, 4.18.3, 4.21.0Yu Bao from PayPalreproducteur
CVE-2026-46457CamelCWE-20 Improper Input Validation4.14.8, 4.18.3, 4.21.0Yu Bao from PayPalreproducteur
CVE-2026-46584Camel MailCWE-200 Exposure of Sensitive Information to an Unauthorized Actor4.14.8, 4.18.3, rYu Bao from PayPalreproducteur
CVE-2026-46587CamelCWE-20 Improper Input Validation4.14.8, 4.18.3, 4.21.0Yu Bao from PayPalreproducteur
CVE-2026-46588CamelCWE-20 Improper Input Validation4.14.8, 4.18.3, 4.21.0Yu Bao from PayPalreproducteur
CVE-2026-47323CamelCWE-178 Improper Handling of Case Sensitivity4.14.6, 4.18.2Quac Tranreproducteur
CVE-2026-49042CamelCWE-20 Improper Input Validation4.18.3, 4.21.0Yu Bao from PayPalreproducteur
CVE-2026-59230Camel MailCWE-20 Improper Input Validation4.14.9, 4.18.4, 4.22.0Atuin - Automated Vulnerability Discovery Engine, anciety of Tencent Xuanwu Labreproducteur
CVE-2026-60093Camel Azure Storage DatalakeCWE-22 Improper Limitation of a Pathname to a Restricted Directory4.14.9, 4.18.4, 4.22.0n0mi1k and Hiep Nguyenreproducteur
CVE-2026-66906Camel Azure Storage BlobCWE-22 Improper Limitation of a Pathname to a Restricted Directory4.14.9, 4.18.4, 4.22.0n0mi1k and Hiep Nguyenreproducteur
CVE-2026-66907Camel Google StorageCWE-22 Improper Limitation of a Pathname to a Restricted Directory4.14.9, 4.18.4, 4.22.0n0mi1kreproducteur
CVE-2026-66908Camel Platform HTTP MainCWE-287 Improper Authentication4.22.0n0mi1kreproducteur
CVE-2026-71300Camel Atmosphere WebsocketCWE-20 Improper Input Validation4.14.9, 4.18.4, 4.22.0Barak Srour from Apiiroreproducteur