Voltar às atualizações
UpdatedSep 3, 2026

security-research — Updated!

Vulnerabilidades que reportei à Apache Software Foundation: 46 CVEs em 15 projetos

Compartilhar

Pesquisa de Segurança

Vulnerabilidades que reportei à Apache Software Foundation, divulgadas através do processo de segurança da ASF. 46 CVEs em 15 projetos, de 2023 a 2026.

Onde existe um reprodutor público, ele está vinculado. Cada um é um projeto mínimo e autocontido que demonstra o problema e indica a versão que o corrigiu.

Em 25 CWEs distintas, duas classes dominam: desserialização de dados não confiáveis (7) e server-side request forgery (7).

Em todo o ecossistema Apache: 16 CVEs, 14 projetos

CVEComponenteClasseCorrigido emPoC
CVE-2023-41313DorisCWE-208 Observable Timing Discrepancy1.2.8-
CVE-2023-41834Flink Stateful FunctionsCWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component3.3.0-
CVE-2023-43123StormCWE-200 Exposure of Sensitive Information to an Unauthorized Actor2.6.0-
CVE-2024-23454HadoopCWE-378 Creation of Temporary File With Insecure Permissions3.4.0-
CVE-2024-23953HiveCWE-208 Observable Timing Discrepancy4.0.0-
CVE-2024-29869HiveCWE-732 Incorrect Permission Assignment for Critical Resource4.0.1-
CVE-2026-28672RangerCWE-77 Improper Neutralization of Special Elements used in a Command2.9.0reprodutor
CVE-2026-34476SkyWalking MCPCWE-918 Server-Side Request Forgerynão publicado-
CVE-2026-40005IoTDBCWE-22 Improper Limitation of a Pathname to a Restricted Directory2.0.10-
CVE-2026-40008IoTDBCWE-470 Use of Externally-Controlled Input to Select Classes or Code2.0.10-
CVE-2026-40564Flink Kubernetes OperatorCWE-918 Server-Side Request Forgery1.15.0reprodutor
CVE-2026-41041GravitinoCWE-177 Improper Handling of URL Encoding1.2.1-
CVE-2026-44616ZeppelinCWE-90 Improper Neutralization of Special Elements used in an LDAP Query0.12.1-
CVE-2026-49361Fluss (incubating)CWE-400 Uncontrolled Resource Consumptionnão publicado-
CVE-2026-63039InLongCWE-89 Improper Neutralization of Special Elements used in an SQL Command2.4.0reprodutor
CVE-2026-64640PolarisCWE-863 Incorrect Authorization1.7.0reprodutor

Apache Camel: 30 CVEs

Camel é o projeto que eu mantenho, então é o que recebe o maior escrutínio. O padrão dominante é cabeçalhos de entrada não filtrados alcançando o plano de controle de um produtor, além de uma longa cauda de desserialização insegura em caminhos de registro e migração.

CVEComponenteClasseCorrigido emPoC
CVE-2024-23114CamelCWE-502 Deserialization of Untrusted Data3.21.4, 3.22.1, 4.0.4, 4.4.0-
CVE-2026-23552CamelCWE-346 Origin Validation Error4.18.0reprodutor
CVE-2026-25747Camel LevelDBCWE-502 Deserialization of Untrusted Data4.10.9, 4.14.5, 4.18.0reprodutor
CVE-2026-27172CamelCWE-502 Deserialization of Untrusted Data4.14.6, 4.18.1reprodutor
CVE-2026-40047CamelCWE-88 Improper Neutralization of Argument Delimiters in a Command4.18.3reprodutor
CVE-2026-40048Camel PQCCWE-502 Deserialization of Untrusted Data4.18.2, 4.20.0reprodutor
CVE-2026-43866CamelCWE-502 Deserialization of Untrusted Data4.14.8, 4.18.3, 4.21.0reprodutor
CVE-2026-43867CamelCWE-502 Deserialization of Untrusted Data4.18.3, 4.21.0reprodutor
CVE-2026-46455CamelCWE-613 Insufficient Session Expiration4.18.3, 4.21.0reprodutor
CVE-2026-46585Camel LuceneCWE-639 Authorization Bypass Through User-Controlled Key4.14.8, 4.18.3, 4.21.0reprodutor
CVE-2026-46590CamelCWE-502 Deserialization of Untrusted Data4.18.3, 4.21.0reprodutor
CVE-2026-46591CamelCWE-943 Improper Neutralization of Special Elements in Data Query Logic4.14.8, 4.18.3, 4.21.0reprodutor
CVE-2026-46592CamelCWE-441 Unintended Proxy or Intermediary4.14.8, 4.18.3, 4.21.0reprodutor
CVE-2026-46726Camel Vertx WebsocketCWE-918 Server-Side Request Forgery4.14.8, 4.18.3, 4.21.0reprodutor
CVE-2026-48203CamelCWE-918 Server-Side Request Forgery4.14.8, 4.18.3, 4.21.0reprodutor
CVE-2026-48204CamelCWE-284 Improper Access Control4.14.8, 4.18.3, 4.21.0reprodutor
CVE-2026-48205Camel DNSCWE-918 Server-Side Request Forgery4.14.8, 4.18.3, 4.21.0reprodutor
CVE-2026-48206Camel JIRACWE-639 Authorization Bypass Through User-Controlled Key4.14.8, 4.18.3, 4.21.0reprodutor
CVE-2026-49086Camel DaprCWE-441 Unintended Proxy or Intermediary4.14.8, 4.18.3, 4.21.0reprodutor
CVE-2026-49097CamelCWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component4.14.8, 4.18.3, 4.21.0reprodutor
CVE-2026-49098CamelCWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component4.14.8, 4.18.3, 4.21.0reprodutor
CVE-2026-49099Camel SalesforceCWE-639 Authorization Bypass Through User-Controlled Key4.14.8, 4.18.3, 4.21.0reprodutor
CVE-2026-49365CamelCWE-209 Generation of Error Message Containing Sensitive Information4.14.8, 4.18.3, 4.21.0reprodutor
CVE-2026-53913Camel KeycloakCWE-636 Not Failing Securely4.18.3, 4.21.0reprodutor
CVE-2026-55993Camel Atmosphere WebsocketCWE-918 Server-Side Request Forgery4.14.8, 4.18.3, 4.21.0reprodutor
CVE-2026-55994Camel IggyCWE-918 Server-Side Request Forgery4.18.3, 4.21.0reprodutor
CVE-2026-56139Camel UndertowCWE-209 Generation of Error Message Containing Sensitive Information4.14.8, 4.18.3, 4.21.0reprodutor
CVE-2026-56140Camel AWS2 SNSCWE-20 Improper Input Validation4.14.8, 4.18.3, 4.21.0-
CVE-2026-63621Camel KnativeCWE-20 Improper Input Validation4.14.9, 4.18.4, 4.22.0reprodutor
CVE-2026-78329Camel UndertowCWE-20 Improper Input Validation4.14.9, 4.18.4, 4.22.0reprodutor

Reprodutores para problemas encontrados por outros: 26

Como mantenedor do Camel, também construo reprodutores para relatos que chegam de fora, para confirmar o problema e validar a correção. Estas não são minhas descobertas. O crédito pertence aos relatores nomeados abaixo.

CVEComponenteClasseCorrigido emReportado porPoC
CVE-2024-22369CamelCWE-502 Deserialization of Untrusted Data3.21.4, 3.22.1, 4.0.4, 4.4.0Ziyang Chen from HuaWei Open Source Management Center, Pingtao Wei from HuaWei Open Source Management Center (finder) and Haoran Zhi from HuaWei Open Source Management Centerreprodutor
CVE-2026-33453CamelCWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes4.18.1, 4.19.0Hyunwoo Kim (@v4bel)reprodutor
CVE-2026-33454CamelCWE-502 Deserialization of Untrusted Data4.14.6, 4.18.1Hyunwoo Kim (@v4bel)reprodutor
CVE-2026-40022Camel Platform HTTP MainCWE-288 Authentication Bypass Using an Alternate Path or Channel4.14.6, 4.18.2Jihang Yureprodutor
CVE-2026-40453Camel JMSCWE-178 Improper Handling of Case Sensitivity4.14.6, 4.18.2, 4.20.0Saroj Khadkareprodutor
CVE-2026-40473Camel MinaCWE-502 Deserialization of Untrusted Data4.14.6, 4.18.2, 4.20.0Venkatraman Kumar from Securinreprodutor
CVE-2026-40858CamelCWE-502 Deserialization of Untrusted Data4.14.7, 4.18.2, 4.20.0Feng Ning from Innora Pte. Ltd.reprodutor
CVE-2026-40859CamelCWE-502 Deserialization of Untrusted Data4.14.8, 4.18.3, 4.20.0Venkatraman Kumar from Securinreprodutor
CVE-2026-40860CamelCWE-502 Deserialization of Untrusted Data4.14.7, 4.18.2, 4.20.0Venkatraman Kumar from Securinreprodutor
CVE-2026-42527CamelCWE-502 Deserialization of Untrusted Data4.14.8, 4.18.3, 4.21.0Venkatraman Kumar from Securin and Yu Bao from Paypalreprodutor
CVE-2026-43865CamelCWE-502 Deserialization of Untrusted Data4.14.8, 4.18.3, 4.21.0gaorenyusireprodutor
CVE-2026-46453CamelCWE-639 Authorization Bypass Through User-Controlled Key4.14.8, 4.18.3, 4.21.0Yu Bao from PayPalreprodutor
CVE-2026-46454CamelCWE-20 Improper Input Validation4.14.8, 4.18.3, 4.21.0Yu Bao from PayPalreprodutor
CVE-2026-46456CamelCWE-20 Improper Input Validation4.14.8, 4.18.3, 4.21.0Yu Bao from PayPalreprodutor
CVE-2026-46457CamelCWE-20 Improper Input Validation4.14.8, 4.18.3, 4.21.0Yu Bao from PayPalreprodutor
CVE-2026-46584Camel MailCWE-200 Exposure of Sensitive Information to an Unauthorized Actor4.14.8, 4.18.3, rYu Bao from PayPalreprodutor
CVE-2026-46587CamelCWE-20 Improper Input Validation4.14.8, 4.18.3, 4.21.0Yu Bao from PayPalreprodutor
CVE-2026-46588CamelCWE-20 Improper Input Validation4.14.8, 4.18.3, 4.21.0Yu Bao from PayPalreprodutor
CVE-2026-47323CamelCWE-178 Improper Handling of Case Sensitivity4.14.6, 4.18.2Quac Tranreprodutor
CVE-2026-49042CamelCWE-20 Improper Input Validation4.18.3, 4.21.0Yu Bao from PayPalreprodutor
CVE-2026-59230Camel MailCWE-20 Improper Input Validation4.14.9, 4.18.4, 4.22.0Atuin - Automated Vulnerability Discovery Engine, anciety of Tencent Xuanwu Labreprodutor
CVE-2026-60093Camel Azure Storage DatalakeCWE-22 Improper Limitation of a Pathname to a Restricted Directory4.14.9, 4.18.4, 4.22.0n0mi1k and Hiep Nguyenreprodutor
CVE-2026-66906Camel Azure Storage BlobCWE-22 Improper Limitation of a Pathname to a Restricted Directory4.14.9, 4.18.4, 4.22.0n0mi1k and Hiep Nguyenreprodutor
CVE-2026-66907Camel Google StorageCWE-22 Improper Limitation of a Pathname to a Restricted Directory4.14.9, 4.18.4, 4.22.0n0mi1kreprodutor
CVE-2026-66908Camel Platform HTTP MainCWE-287 Improper Authentication4.22.0n0mi1kreprodutor
CVE-2026-71300Camel Atmosphere WebsocketCWE-20 Improper Input Validation4.14.9, 4.18.4, 4.22.0Barak Srour from Apiiroreprodutor

As descobertas são reportadas de forma privada à equipe de segurança relevante da ASF e publicadas somente após a disponibilização de uma correção. Os reprodutores têm como alvo a versão vulnerável e destinam-se a defensores que validam sua própria exposição.

Categorias