Apache: 25 Vulnerabilities Across Tomcat, Camel, Hive, and More Disclosed Aug 24-26
Apache projects including Tomcat, Camel, and Hive were hit with 25 vulnerabilities disclosed Aug 24-26, 2026, featuring critical auth bypasses and path traversals.

Key findings
- 25 vulnerabilities disclosed across Apache Tomcat, Camel, Hive, APISIX, Allura, and DolphinScheduler between Aug 24-26, 2026.
- Critical authentication bypass and authorization flaws in Apache Tomcat (CVE-2026-65905, CVE-2026-65182, CVE-2026-68525).
- Multiple critical vulnerabilities in Apache Camel include path traversal and input validation issues (CVE-2026-66906, CVE-2026-71300, CVE-2026-78329).
- Apache Hive critical vulnerabilities include SSRF and SQL injection in Metastore (CVE-2026-55976, CVE-2026-49845).
- Patches released for Tomcat, Camel, Hive, Allura, and DolphinScheduler; prompt upgrades are essential.
On August 25, 2026, a significant batch of 25 vulnerabilities was disclosed across multiple Apache projects, with a notable cluster impacting Apache Tomcat and Apache Camel. The disclosures, spanning from August 24 to August 26, 2026, highlight a range of security weaknesses including critical authentication bypasses, authorization flaws, and resource consumption issues. These vulnerabilities affect widely used components, emphasizing the need for prompt patching and security reviews for organizations utilizing Apache software.
The Apache Tomcat vulnerabilities, disclosed on August 25, 2026, represent a serious concern for users of this popular Java servlet container. Among the most critical are CVE-2026-65905 (CVSSv3 9.8) and CVE-2026-65637 (CVSSv3 9.8), both related to authentication bypass and improper input validation, with CVE-2026-65637 being an incomplete fix for a previous vulnerability. CVE-2026-65182 (CVSSv3 9.1) and CVE-2026-68525 (CVSSv3 9.1) involve improper access control and authorization bypasses, respectively, allowing attackers to circumvent security constraints. Other high-severity flaws include CVE-2026-68569 (CVSSv3 8.1) for improper authentication and CVE-2026-66422 (CVSSv3 8.1) for improper authorization due to incorrect security-role-ref definitions. CVE-2026-68763 (CVSSv3 7.5) addresses uncontrolled resource consumption via an HTTP/2 backlog leak, and CVE-2026-65927 (CVSSv3 7.5) involves an off-by-one error in rewrite valve processing. CVE-2026-73180 (CVSSv3 6.8) points to insufficient session expiration in WebSocket connections.
Apache Camel, a popular integration framework, was also heavily impacted, with vulnerabilities disclosed on August 24, 2026. Several critical flaws (CVSSv3 9.8) were found in various components, including CVE-2026-78329 in the Undertow component, CVE-2026-71300 in the Atmosphere Websocket component, and CVE-2026-49845 in Apache Hive's Metastore. Apache Camel also suffers from critical relative path traversal vulnerabilities, such as CVE-2026-66906 in the Azure Storage Blob component and CVE-2026-66907 in the Google Storage component. CVE-2026-60093 presents a similar relative path traversal risk in the Azure Storage Datalake component. Improper authentication in the Platform HTTP Main component (CVE-2026-66908, CVSSv3 7.5) and improper input validation in the mail component (CVE-2026-59230, CVSSv3 6.5) are also notable. CVE-2026-59295 highlights a memory leak in HttpAsyncClient usage.
Beyond Tomcat and Camel, other Apache projects experienced disclosures. Apache Hive faced critical vulnerabilities including CVE-2026-55976 (CVSSv3 9.1) for Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution and CVE-2026-49845 (CVSSv3 9.8) for SQL injection in Metastore partition-name resolution. CVE-2026-53561 (CVSSv3 7.4) in HiveServer2 SAML bearer-token validation allows for authentication as an arbitrary user. Apache APISIX had CVE-2026-63041 (Medium) related to untrusted input in the attach-consumer-label plugin, potentially leading to privilege escalation or authorization bypass. Apache Allura's CVE-2026-75099 (CVSSv3 5.3) involves unauthenticated REST disclosure of certain content items. Apache DolphinScheduler's CVE-2026-49050 (High, CVSSv3 8.8) allows general users to mint admin access tokens.
The response to these vulnerabilities has been swift, with multiple projects releasing patched versions. Apache Tomcat versions 11.0.25, 10.1.58, and 9.0.121 address many of the disclosed flaws, including the critical CVE-2026-65637. Apache Camel has released updates with specific version ranges provided for each affected component, such as 4.14.9, 4.18.4, and 4.22.0. Apache Hive versions before 4.2.1 are affected by CVE-2026-55976 and CVE-2026-49845, recommending an upgrade to 4.2.1. Apache Allura users should upgrade to version 1.20.0 to fix CVE-2026-75099, and Apache DolphinScheduler users should upgrade to version 3.4.2 to address CVE-2026-49050.
This coordinated disclosure across various Apache projects underscores the importance of maintaining up-to-date software and regularly reviewing security advisories. The breadth of affected products and the severity of some vulnerabilities, particularly the authentication bypass and authorization flaws in Tomcat and Hive, necessitate immediate attention from system administrators and security teams to prevent potential exploitation. Continuous monitoring and prompt application of patches are crucial for mitigating risks associated with this extensive batch of security issues.
CVEs by Product
Apache Tomcat
- CVE-2026-73180 (Medium)
- CVE-2026-68763 (High)
- CVE-2026-68569 (High)
- CVE-2026-68525 (Critical)
- CVE-2026-66422 (High)
- CVE-2026-65927 (High)
- CVE-2026-65905 (Critical)
- CVE-2026-65637 (Critical)
- CVE-2026-65183 (High)
- CVE-2026-65182 (Critical)
Apache Camel
- CVE-2026-78329 (Critical)
- CVE-2026-71300 (Critical)
- CVE-2026-66908 (High)
- CVE-2026-66907 (High)
- CVE-2026-66906 (Critical)
- CVE-2026-63621 (Medium)
- CVE-2026-60093 (Medium)
- CVE-2026-59230 (Medium)
- CVE-2026-59295 (Medium)
Apache Hive
- CVE-2026-55976 (Critical)
- CVE-2026-53561 (High)
- CVE-2026-49845 (Critical)
Apache APISIX
- CVE-2026-63041 (Medium)
Apache Allura
- CVE-2026-75099 (Medium)
Apache DolphinScheduler
- CVE-2026-49050 (High)