apache
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 1000 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 9, 2026 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Apache Struts: Unbounded read of a JSON request body
Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API)
CVE-2026-66256: Apache Shindig Common, Apache Shindig Social-Api: mote Code Execution via XStam deserialization (OpenSocial ST API)
CVE-2026-71290: Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)
CVE-2026-64607: Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
Apache Allura: XSS in markdown pipeline
Apache Allura: XSS in code display
Apache Allura: Missing permission checks IDOR
Apache Allura: Git command injection
Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI
Monitor apache in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.