VYPR
advisoryPublished Oct 9, 2026· Updated Oct 10, 2026· 1 source

Apache Projects Hit by 25 Vulnerabilities in October 2026 Disclosure Batch

Key findings • 25 CVEs disclosed across Apache Camel, CXF, DolphinScheduler, Geode, Jackrabbit, and YuniKorn from Oct 7-9, 2026. • Multiple Apache CXF vulnerabilities include input validation…

Key findings

  • 25 CVEs disclosed across Apache Camel, CXF, DolphinScheduler, Geode, Jackrabbit, and YuniKorn from Oct 7-9, 2026.
  • Multiple Apache CXF vulnerabilities include input validation, path traversal, token handling, and DoS flaws.
  • Apache DolphinScheduler faces critical authorization bypass and information disclosure vulnerabilities.
  • Apache Jackrabbit has critical session fixation and arbitrary class instantiation vulnerabilities.
  • Affected Apache projects include Camel, CXF, DolphinScheduler, Geode, Jackrabbit, and YuniKorn.
  • Ranging from Low to Critical severity, users must apply patches for affected Apache components.

On October 7-9, 2026, a significant batch of 25 vulnerabilities was disclosed across multiple Apache Software Foundation projects, including Apache Camel, CXF, DolphinScheduler, Geode, Jackrabbit, and YuniKorn. These vulnerabilities, ranging in severity from Low to Critical, highlight a broad range of security weaknesses affecting various components and functionalities within the Apache ecosystem. The disclosures, clustered over a two-day period, underscore the need for diligent patching and security review for users of these widely adopted open-source projects.

Several vulnerabilities were identified within Apache CXF, a widely used framework for developing and consuming web services. CVE-2026-103413 and CVE-2026-103412, both rated High, stem from improper input validation and path traversal flaws in the Karavan component, potentially allowing for arbitrary resource application and file system manipulation. Within the broader CXF framework, CVE-2026-97791 and CVE-2026-97468 expose weaknesses in security token validation and caching mechanisms, enabling attackers to potentially forge or reuse security tokens. Additionally, CVE-2026-86463 points to a denial-of-service vulnerability in the FIQL query parser due to excessive CPU consumption with crafted queries. Other CXF-related issues include an open redirect vulnerability (CVE-2026-79650), a potential denial-of-service via excessive memory and CPU consumption in XML parsing (CVE-2026-108039), and a hostname verification flaw in the Netty-based HTTP client transport (CVE-2026-107938). The OIDC relying-party component is affected by an authentication freshness check bypass (CVE-2026-71575), and the JPA OAuth2 authorization code grant provider suffers from a race condition allowing multiple access tokens from a single code (CVE-2026-73179). Finally, CVE-2026-107937 highlights incomplete enforcement of attachment header size limits in multipart/MTOM processing, and CVE-2026-100227 indicates improper verification of XML signatures.

Apache DolphinScheduler users face authorization vulnerabilities, with CVE-2026-71896 and CVE-2026-71895 allowing authenticated users to retrieve sensitive account information and Kubernetes configuration data, respectively. CVE-2026-71183 permits unauthorized access to data source information. Several high-severity authorization bypass flaws (CVE-2026-66087, CVE-2026-66084, CVE-2026-66082) enable authenticated users to operate task instances, modify task definitions, and perform unauthorized operations on workflow schedules and definitions across projects they should not have access to.

Apache Jackrabbit, a content repository, has two disclosed vulnerabilities. CVE-2026-92415, a Medium severity issue, allows arbitrary class instantiation via a malicious server due to improper handling of externally controlled input in the WebDAV/DavEx client. More critically, CVE-2026-92414 (Critical severity) suffers from session fixation and reuse, where authenticated sessions can be attached to any matching header token without a proper credential check.

Other projects affected include Apache Geode, with CVE-2026-103371 (High) allowing sensitive information to be logged in the Web Management interface. Apache YuniKorn, a container scheduler, has two Low severity vulnerabilities: CVE-2026-97146 allows bypassing user annotation checks via secondary labels, and CVE-2026-92393 bypasses label and user annotation checks for workload UPDATE actions. CVE-2026-78243 (Low) in YuniKorn can lead to a crash when processing LDAP group membership entries if configured with the LDAP group resolver.

The majority of these vulnerabilities were disclosed on October 9, 2026, with a few appearing on October 7 and 8. Users of Apache Camel, CXF, DolphinScheduler, Geode, Jackrabbit, and YuniKorn are strongly advised to review the specific CVE details and apply the necessary patches or updates. The broad nature of these disclosures across multiple projects highlights the importance of continuous security monitoring and timely remediation within the Apache ecosystem.

The Apache Software Foundation has released updates for the affected components. For Apache CXF, users should consult the official advisories for specific version information. Apache DolphinScheduler versions 2.0.0 and later, and Apache Jackrabbit versions 2.23.1 and later, address these issues. Apache Geode versions 2.0.3 and later are recommended. Apache YuniKorn versions 1.9.1 and later are available to fix the disclosed vulnerabilities. Users are urged to upgrade to the fixed versions to mitigate these security risks.

This batch of vulnerabilities underscores the dynamic nature of security in open-source software. The wide range of affected projects and vulnerability types—from input validation and path traversal to authorization bypasses and session fixation—necessitates a comprehensive approach to security management for organizations relying on Apache projects. Staying informed about coordinated disclosure events and promptly applying security updates remains critical for maintaining a secure operating environment.

CVE-2026-103413, CVE-2026-103412, CVE-2026-97791, CVE-2026-97468, CVE-2026-86463, CVE-2026-79650, CVE-2026-78384, CVE-2026-73179, CVE-2026-71575, CVE-2026-108039, CVE-2026-107938, CVE-2026-107937, CVE-2026-100227, CVE-2026-71896, CVE-2026-71895, CVE-2026-71183, CVE-2026-66087, CVE-2026-66084, CVE-2026-66082, CVE-2026-103371, CVE-2026-92415, CVE-2026-92414, CVE-2026-97146, CVE-2026-92393, CVE-2026-78243

Synthesized by Vypr AI