Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2670+ Articles
165+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
8 articles

#Apache

All CosmicBytez Labs articles tagged #Apache, across news, security advisories, how-to guides, and projects.

  • SecurityAug 12, 2026

    Apache HttpComponents TLS Hostname Verification Bypass

    Apache HttpComponents Client 5.4+ async mode ignores HostnameVerificationPolicy#BUILTIN, enabling MITM attacks against TLS connections in affected applications.

  • NewsAug 7, 2026

    AI-Assisted HTTP Terminator Finds Novel Desync Techniques and Apache Zero-Day

    PortSwigger researcher James Kettle unveiled HTTP Terminator at Black Hat USA 2026 — an autonomous AI system that invented three new HTTP request smuggling techniques and discovered an Apache Traffic Server zero-day by testing 30,000 attack vectors across 30,000 websites.

  • SecurityJul 30, 2026

    CVE-2026-58155: Apache Traffic Server Header Truncation Enables Request Smuggling and Policy Bypass

    A critical vulnerability in Apache Traffic Server allows attackers to exploit over-long header name truncation to alias headers, smuggle HTTP requests, and bypass security policies. CVSS 9.3 — all 8.x, 9.x, and 10.x branches affected.

  • SecurityJul 22, 2026

    CVE-2026-64606: Apache Fury Critical Deserialization Flaw (CVSS 9.8)

    A critical deserialization vulnerability in Apache Fury allows attackers to bypass class-registration checks during Java lambda deserialization, enabling...

  • SecurityJul 15, 2026

    CVE-2026-59084: Apache Tomcat EncryptInterceptor Misconfiguration Risk (CVSS 9.1)

    Apache Tomcat's EncryptInterceptor cluster encryption feature has been insufficiently documented since version 9.0.13, leaving deployments vulnerable to...

  • SecurityJun 27, 2026

    CVE-2025-55017: Apache IoTDB Critical Path Traversal Vulnerability

    Critical path traversal vulnerability (CVSS 9.1) in Apache IoTDB affects versions 1.0.0 through 1.3.5 and 2.0.0 through 2.0.5. Users must upgrade...

  • SecurityJun 27, 2026

    CVE-2025-64152: Apache IoTDB Second Critical Path Traversal Flaw

    A second critical path traversal vulnerability (CVSS 9.1) in Apache IoTDB affects versions 1.0.0 through 1.3.5 and 2.0.0 through 2.0.6. Patch to 1.3.6 or...

  • NewsMay 10, 2026

    Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS

    The Apache Software Foundation has released urgent security updates for the Apache HTTP Server addressing a severe vulnerability in the HTTP/2 protocol...