Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
3874 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (0.5) | 0.56% | — | Apache Nifi | 16/9/2026 | 21/9/2026 | Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization checking on Assets and Secrets referenced in proposed configuration. Updating or verifying a Connector configuration step can apply Asset and Secret references, but framework… | |
| Analizada | Alta (7.5) | 0.62% | — | Apache Nifi | 16/9/2026 | 21/9/2026 | Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip encoding. The framework enforcement filter did not check multiple instances of the Content-Encoding header and did not reject… | |
| Modificada | Media (6.5) | 0.81% | — | Apache-airflow-providers-akeyless | 16/9/2026 | 17/9/2026 | Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator that causes the backend to resolve a secret belonging to a different team,… | |
| Analizada | Alta (8.8) | 1.2% | — | Apache-airflow-providers-apache-kafka | 16/9/2026 | 18/9/2026 | Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with no allowlist, and hand them to the confluent-kafka client which invokes them. Deployments that have enabled the Kafka event producer… | |
| Analizada | Alta (8.1) | 0.37% | — | Apache-airflow-providers-fab | 16/9/2026 | 18/9/2026 | Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts. An attacker holding a token that the same Authentik identity provider minted for a different client application can present it to Airflow and be authenticated as the… | |
| Analizada | Media (5.3) | 0.74% | — | Apache Zookeeper | 16/9/2026 | 18/9/2026 | An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted add_auth("ensemble", ...) request containing newline characters (\n). When the ensemble name doesn't match, EnsembleAuthenticationProvider.handleAuthentication() logs the raw, unsanitized name… | |
| Analizada | Media (5.3) | 0.74% | — | Apache Zookeeper | 16/9/2026 | 18/9/2026 | When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields into Apache ZooKeeper's audit log by sending a digest authentication request with tab characters (\t) embedded in the username. Because the audit log uses tab-separated key=value format, the injected… | |
| Analizada | Alta (7.2) | 1.0% | — | Apache-airflow-providers-fab | 16/9/2026 | 18/9/2026 | Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password authentication correctly rejects the disabled account, but the Core API continues to accept an existing, unexpired token naming it, and lets that token mint a replacement — so the account… | |
| Analizada | Alta (7.5) | 0.60% | — | Apache Zookeeper | 16/9/2026 | 18/9/2026 | The `deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authenticated client to delete specific znodes in the data tree regardless of the ACL restrictions on the znode or its parent. This opcode is considered internal-only and the official client doesn't have… | |
| Analizada | Crítica (9.8) | 0.98% | — | Apache-airflow-providers-keycloak | 16/9/2026 | 18/9/2026 | Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client registered in the Keycloak realm, not only the client configured for Airflow. No allowlist restricts which client ids may authenticate, so the credentials of an unrelated application that… | |
| Analizada | Crítica (9.1) | 0.81% | — | Apache-airflow-providers-keycloak | 16/9/2026 | 18/9/2026 | Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak access and refresh tokens used for every authorization decision from separate, unauthenticated cookies, and never checks that the two describe the same… | |
| Analizada | Alta (7.5) | 0.33% | — | Apache Zookeeper | 16/9/2026 | 18/9/2026 | Apache ZooKeeper quorum TLS fails to enforce peer hostname verification in FIPS-mode deployments. When sslQuorum=true, zookeeper.fips-mode=true, ssl.quorum.hostnameVerification=true, and ssl.quorum.clientHostnameVerification=true are enabled, the Java SSLSocket quorum path accepts a CA-trusted peer certificate whose… | |
| Analizada | Alta (7.5) | 0.55% | — | Apache Zookeeper | 16/9/2026 | 18/9/2026 | Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check. An attacker can discover ACL-restricted paths by registering exists-watches on non-existent paths, then reconnecting after the paths are created with restricted ACLs. Issue is caused by incomplete fix for… | |
| Analizada | Crítica (9.1) | 0.83% | — | Apache-airflow-providers-fab | 16/9/2026 | 18/9/2026 | Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who already holds a copy of the victim's session cookie keeps full access as that user after the password change, so the password reset does… | |
| Analizada | Crítica (9.8) | 0.98% | — | Apache-airflow-providers-fab | 16/9/2026 | 18/9/2026 | Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented behaviour that it does. The cleanup compares the string identifier Flask-Login stores in the session against the user's integer database identifier, so the comparison never matches… | |
| Pendiente de análisis | Media (5.4) | 0.25% | — | Apache KafkaAILinuxfoundation StrimziAI | 15/9/2026 | 30/9/2026 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, deploying only the Topic Operator or only the User Operator through the Kafka custom resource leaves the Entity Operator ServiceAccount with RBAC permissions for both… | |
| Pendiente de análisis | Alta (8) | 0.29% | — | Apache KafkaAILinuxfoundation StrimziAI | 15/9/2026 | 30/9/2026 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, an attacker who can create a Kafka custom resource can set Kafka.spec.entityOperator watchedNamespace to a target namespace, causing the Cluster Operator to create a Role… | |
| Aplazada | Alta (8.2) | 1.1% | — | Xwiki PlatformAIEclipse JettyAIApache TomcatAI | 14/9/2026 | 30/9/2026 | XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended skin or web-application resource prefix when Jetty 12 or later decodes the request path. The affected lookup is replaced… | |
| Aplazada | Alta (8.1) | 0.21% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP components served to an authenticated user. The Logviewer reflected the request's `Origin` header back in `Access-Control-Allow-Origin` while also sending `Access-Control-Allow-Credentials: true`. The… | |
| Aplazada | Media (4.3) | 0.28% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content. For daemon logs those settings were not applied: the access decision combined the "this is a daemon log" flag with the authorizer result in a way that discarded the authorizer's answer whenever the flag… | |
| Aplazada | Crítica (9.8) | 0.65% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place. It allocated buffers sized from a length field carried in the frame, so a single frame from an unauthenticated peer able to reach a worker… | |
| Aplazada | Crítica (10) | 0.50% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. Nimbus then served that configuration verbatim to any caller holding read-only topology permissions, so a user whose only grant was the… | |
| Aplazada | Media (6.5) | 0.34% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check. Where the cluster is configured with them, that response includes `storm.zookeeper.auth.payload` and the keystore and truststore passwords for the Thrift, Netty and ZooKeeper TLS… | |
| Aplazada | Alta (8.1) | 0.37% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalance operation accepts configuration overrides and stripped a small set of keys from them, but never re-ran that validation, so a caller authorised to rebalance a topology could introduce a blobstore map… | |
| Aplazada | Crítica (9.8) | 0.39% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, before `nimbus.groups` was considered. An operator who restricted cluster access by group alone, leaving `nimbus.users` unset, therefore received no restriction at all: every authenticated principal… |