Tag: apache
-
Apache Superset SQL Injection Flaw Gets Public PoC Exploit
A public proof-of-concept exploit has been released for CVE-2026-23980, a SQL injection vulnerability affecting Apache Superset installations running versions earlier than 6.0.0. The Apache Superset project disclosed this issue in February. It classified it as an improper neutralization of special elements in a SQL command. Apache reports that the vulnerability allows an authenticated user with…
-
SSO for Apache with mod_auth_openidc: A Complete Guide
Enforcing enterprise SSO at the Apache layer means mod_auth_openidc: Apache becomes the OpenID Connect relying party, authenticates the user before any request reaches your application, and passes identity downstream in headers. Your application code changes very little, sometimes not… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/sso-for-apache-with-mod_auth_openidc-a-complete-guide/
-
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting.Check Point Research said it has tracked the campaign since mid-2025.The modules First seen on…
-
Apache Tomcat Flaws Let Attackers Bypass Authentication and Security Controls, Trigger DoS Attacks
Apache has released version 11.0.25 of Apache Tomcat to address ten security vulnerabilities, including multiple flaws that could lead to authentication bypasses, access-control evasion, and denial-of-service (DoS) conditions. The most serious issues affect Tomcat’s processing of security constraints, authentication mechanisms, HTTP/2 implementation, and behavior of the RewriteValve. All ten vulnerabilities impact releases of Apache Tomcat…
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
A Reported Log4j RCE Is More Complicated Than It Looks
<div cla TL;DR A recently circulated Log4j finding demonstrates a reproducible bypass of a defense-in-depth deserialization control involving FilteredObjectInputStream. Sonatype does not currently consider this a clear-cut Log4j vulnerability. Apache explicitly warns that deserializing untrusted data is unsafe and treats these filters as hardening measures rather than complete security boundaries. Exploitation requires uncommon, legacy-style application…
-
Critical Apache HttpComponents Client Flaw Lets Attackers Impersonate Servers
A critical vulnerability in the Apache HttpComponents Client can allow man-in-the-middle attackers to impersonate trusted servers when applications use the asynchronous version of HttpClient. This vulnerability is tracked as CVE-2026-71290 and arises from improper TLS hostname verification in Apache HttpComponents Client versions 5.4 through 5.6.3. Apache HttpComponents Client Flaw The issue specifically affects applications configured…
-
AzureOAuth-Login unsicher – Apache Airflow ermöglicht Umgehung der Authentifizierung
First seen on security-insider.de Jump to article: www.security-insider.de/apache-airflow-fab-oauth-bypass-update-3-7-3-a-f17d8f692a37e6884f8b1018e6de7a27/
-
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors.PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where scanning First seen on thehackernews.com Jump…
-
Enterprise Java Vulnerabilities Enable Pre-Auth RCE in Bonita BPM and Apache OFBiz
Security research presented at Black Hat 2026 has identified 12 vulnerabilities across four enterprise Java platforms, including two critical pre-authentication remote code execution (RCE) chains affecting Bonita BPM and Apache OFBiz. Researchers Lidor Ben Shitrit and Assaf Levkovich demonstrated how seemingly minor middleware vulnerabilities, such as differences in URL parsing, incomplete servlet protections, hardcoded cryptographic…
-
U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The first issue added to the catalog, tracked as CVE-2026-9198, is a critical issue in IBM…
-
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
The U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-langflow-n-central-apache-tomcat-flaws/
-
Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code
Tags: apache, authentication, cve, cyber, flaw, injection, remote-code-execution, service, sql, vulnerabilityApache Syncope has released versions 4.1.24.1, 4.1.24.1.2, and 4.0.74.0.7 to address six security vulnerabilities affecting the 4.1, 4.0, and 3.0 release branches. These vulnerabilities include a self-service privilege escalation bug, multiple post-authentication remote code execution (RCE) pathways, authenticated server-side request forgery (SSRF), and SQL injection issues. Apache Syncope Flaws CVE-2026-62183 affects deployments that utilize the…
-
SpaceXAI Open-Sources Grok Build After Privacy Backlash
SpaceXAI open-sourced Grok Build under Apache 2.0 after privacy backlash over broad directory uploads from its terminal AI coding agent. The post SpaceXAI Open-Sources Grok Build After Privacy Backlash appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-spacexai-grok-build-open-source-privacy/
-
Attackers Combine MCP Recon With Cloud Metadata SSRF to Steal Service Account Tokens
Internet-wide reconnaissance is expanding beyond conventional application targets to include Model Context Protocol (MCP) services, AI assistant configuration files, and locally exposed LLM endpoints. A 14-day review of Apache and ModSecurity logs from a small, low-traffic shared host found roughly 200 requests tied to AI-agent reconnaissance, alongside routine WordPress, .env, Git, and Spring Boot Actuator…
-
Debian 13.6 Released With Security Updates for Linux, Apache, Curl, QEMU, and More
The Debian Project has released Debian 13.6, the sixth point update for its stable Debian 13 “trixie” distribution. This update, released on July 11, 2026, includes a collection of security fixes, critical bug corrections, and updated installation images. It does not introduce a new version of Debian; existing systems can be upgraded to the latest…
-
Apache Tomcat Vulnerabilities Let Attackers Bypass Authentication and Security Constraints
The Apache Software Foundation has disclosed two security vulnerabilities in Apache Tomcat that can lead to authentication bypass and improper enforcement of security constraints. These vulnerabilities impact various deployments across enterprise environments. They are tracked as CVE-2026-55957 (Important severity) and CVE-2026-55956 (Moderate severity) and affect multiple supported versions of Tomcat. If left unpatched, these issues…
-
Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
Tags: apache, attack, control, cybersecurity, flaw, github, google, microsoft, open-source, supply-chainCybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains.The “critical exploitable pattern” has been codenamed Cordyceps by Novee Security. The issue can allow full attacker control of repositories at dozens of the largest organizations worldwide, including Microsoft, Google, Apache, and First seen…
-
‘Cordyceps’: Mushrooming Malicious Pull Requests Threaten Developer Workflows
The CI/CD workflow weakness affects Microsoft’s Azure Sentinel, Google’s AI Agent Development Kit, Apache’s Doris analytics database, Cloudflare’s Workers SDK, and Python Software Foundation’s Black. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/cordyceps-malicious-pull-requests-developer-workflows
-
‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking
Novee Security reveals Cordyceps, a CI/CD vulnerability in GitHub Actions workflows that let anonymous users poison builds and expose tokens across major projects today. First seen on hackread.com Jump to article: hackread.com/cordyceps-ci-cd-flaw-microsoft-google-apache-repos-hijack/
-
‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking
Novee Security reveals Cordyceps, a CI/CD vulnerability in GitHub Actions workflows that let anonymous users poison builds and expose tokens across major projects today. First seen on hackread.com Jump to article: hackread.com/cordyceps-ci-cd-flaw-microsoft-google-apache-repos-hijack/
-
Apache HTTP Server 2.4.68 Patches Multiple Security Vulnerabilities
Apache has released HTTP Server version 2.4.68, addressing multiple security vulnerabilities across core modules and widely deployed components, reinforcing the importance of timely patching in internet-facing infrastructure. The update resolves a mix of memory safety issues, privilege escalation flaws, denial-of-service conditions, and input validation weaknesses affecting versions ranging from 2.4.0 through 2.4.67. While several issues…
-
Nur ein Client nötig: HTTP/2 Bomb legt Webserver in Sekunden lahm
Bei gängigen Webservern wie Nginx, Apache HTTPD und Microsoft IIS lässt sich mit wenig Aufwand innerhalb von Sekunden der Speicher fluten. First seen on golem.de Jump to article: www.golem.de/news/nur-ein-client-noetig-http-2-bomb-legt-webserver-in-sekunden-lahm-2606-209396.html
-
Sammelupdate schließt 17 Schwachstellen in Apache OFBiz – Kritische OFBiz-Lücken erlauben Codeausführung ohne Anmeldung
First seen on security-insider.de Jump to article: www.security-insider.de/apache-ofbiz-24-09-06-17-schwachstellen-rce-codeausfuehrung-a-15f5e02dfc4ce184f65ec0d9c373916a/
-
Critical Apache ActiveMQ Vulnerability Exposes Systems to Security Header Injection Attacks
Apache ActiveMQ users are being urged to apply immediate patches following the disclosure of a critical vulnerability, CVE-2026-42253, that enables HTTP response header injection via improperly handled JMS message properties. The flaw affects both Apache ActiveMQ and ActiveMQ Web components. It has been rated with “important” severity by the Apache Software Foundation. CVE-2026-42253: HTTP Response…
-
New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora.The vulnerability has been codenamed HTTP/2 Bomb by Calif.”The vulnerable behavior exists in each server’s default HTTP/2 configuration,” the company said, adding it was discovered by OpenAI Codex by chaining First seen on…
-
HTTP/2 Bomb Remote DoS Exploit Impacts nginx, Apache, IIS, Envoy, and Cloudflare Pingora
A newly disclosed “HTTP/2 Bomb” attack is raising serious concerns across the web infrastructure ecosystem, enabling remote denial-of-service (DoS) conditions against widely deployed servers including nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora. Overview of the HTTP/2 Bomb Attack Security researcher Quang Luong, working with the Codex team, uncovered a novel exploitation technique that…

