Apache

Over 500 Apache Tika Toolkit Instances Exposed To Critical XXE Vulnerability

Security researchers have uncovered a severe flaw in Apache Tika, a popular open-source toolkit for content analysis and extraction. CVE-2025-66516…

4 months ago

Critical Flaw In Apache Tika Core Enables Exploitation Through Malicious PDF Files

A critical XML External Entity (XXE) vulnerability in Apache Tika, tracked as CVE-2025-66516, exposes users to attacks through specially crafted…

5 months ago

Critical Apache Struts Vulnerability Lets Hackers Overwhelm System Storage

A new denial-of-service vulnerability in Apache Struts exposes web applications to disk exhaustion attacks, in which hackers flood servers with…

5 months ago

Critical Flaw In Apache bRPC Framework Allows Remote Server Crash Exploits

Apache bRPC versions before 1.15.0 are vulnerable to a critical remote denial-of-service flaw that allows attackers to crash servers by…

5 months ago

Vulnerability In Apache SkyWalking Exposes Users To Potential XSS Exploits

Apache SkyWalking, a popular open-source tool for application performance monitoring, faces a stored cross-site scripting vulnerability tracked as CVE-2025-54057. This…

5 months ago

Multiple Vulnerabilities In Apache OpenOffice Result In Memory Corruption and Unauthorized Content Loading

Apache OpenOffice, a widely used open-source office suite, has long been a target for security researchers due to its robust…

6 months ago

Apache bRPC Vulnerability Enables Remote Service Crash

A critical vulnerability in Apache bRPC's Redis protocol parser has been identified that allows remote attackers to execute denial-of-service attacks…

9 months ago

New Release – Apache HTTP Server 2.4.64 Fixes 8 Critical Vulnerabilities

The Apache Software Foundation has released Apache HTTP Server 2.4.64 on July 10, 2025, addressing eight significant security vulnerabilities that…

10 months ago

Apache APISIX Vulnerability Enables Unauthorized Cross-Issuer Access via Misconfigurations

Apache APISIX, a popular open-source API gateway, has disclosed a critical security vulnerability affecting versions prior to 3.12.0 that could…

10 months ago

Apache Seata Vulnerability Enables Deserialization of Malicious Data

A newly disclosed security vulnerability in Apache Seata, a distributed transaction solution, exposes applications to potential remote code execution through…

10 months ago