| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Known vulnerabilities affecting Apache products and systems
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-8503 | Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids. Apache::Session::Generate::SHA256 generated session ids insecurely. The default session id generator ret... | 6.5 | 216 | Neutral | No |
| Yes |
| CVE-2026-78329 | Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.11.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. Unde... | 9.8 | 776 | Neutral | Yes | Yes |
| CVE-2026-76986 | Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.AbstractSingleSelectChoice, the base class of DropDownChoice, writes the body of the d... | 6.1 | 272 | Neutral | No | Yes |
| CVE-2026-76985 | Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.extensions.markup.html.form.palette.component.AbstractOptions, which renders the two option lists of a ... | 5.4 | 223 | Neutral | No | Yes |
| CVE-2026-76984 | Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.head.MetaDataHeaderItem generates <meta> and <link> header tags. It escaped the attribute names ... | 5.4 | 223 | Neutral | No | Yes |
| CVE-2026-76983 | Improper neutralization of input during web page generation in Apache Wicket. The <wicket:label> tag is provided by org.apache.wicket.markup.html.form.AutoLabelTextResolver, which is registered by de... | 5.4 | 223 | Neutral | No | Yes |
| CVE-2026-76982 | Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.Button clears the escape-model-strings flag in its constructor, so that the value attr... | 5.4 | 223 | Neutral | No | Yes |
| CVE-2026-75802 | AjaxEditableChoiceLabel in wicket-extensions, when constructed with a non-null IChoiceRenderer, writes the display value obtained from that renderer into the label's markup without applying the HTML e... | 5.4 | 223 | Neutral | No | Yes |
| CVE-2026-75099 | Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through 1.19.1. Users are recommended to upgrade to version 1.20.0, which fixes the i... | 5.3 | 188 | Neutral | No | Yes |
| CVE-2026-75020 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry in the LDAP directory can authe... | 8.1 | 605 | Neutral | No | Yes |
| CVE-2026-75005 | Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes. This issue af... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-74848 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-73635 | Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, ... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-73634 | Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory wi... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-73633 | Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into mem... | 7.5 | 487 | Neutral | Yes | Yes |
| CVE-2026-73632 | Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content asso... | 4.3 | 99 | Neutral | No | Yes |
| CVE-2026-73631 | Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state could be shared across concurrent requests, allowing data associated with one req... | 4.3 | 99 | Neutral | No | Yes |
| CVE-2026-73240 | Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the ... | 9.8 | 588 | Neutral | No | Yes |
| CVE-2026-73239 | Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgra... | 6.5 | 209 | Neutral | No | Yes |
| CVE-2026-73238 | XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue. | 6.1 | 165 | Neutral | No | Yes |