All CosmicBytez Labs articles tagged #Apache, across news, security advisories, how-to guides, and projects.
Apache HttpComponents Client 5.4+ async mode ignores HostnameVerificationPolicy#BUILTIN, enabling MITM attacks against TLS connections in affected applications.
PortSwigger researcher James Kettle unveiled HTTP Terminator at Black Hat USA 2026 — an autonomous AI system that invented three new HTTP request smuggling techniques and discovered an Apache Traffic Server zero-day by testing 30,000 attack vectors across 30,000 websites.
A critical vulnerability in Apache Traffic Server allows attackers to exploit over-long header name truncation to alias headers, smuggle HTTP requests, and bypass security policies. CVSS 9.3 — all 8.x, 9.x, and 10.x branches affected.
A critical deserialization vulnerability in Apache Fury allows attackers to bypass class-registration checks during Java lambda deserialization, enabling...
Apache Tomcat's EncryptInterceptor cluster encryption feature has been insufficiently documented since version 9.0.13, leaving deployments vulnerable to...
Critical path traversal vulnerability (CVSS 9.1) in Apache IoTDB affects versions 1.0.0 through 1.3.5 and 2.0.0 through 2.0.5. Users must upgrade...
A second critical path traversal vulnerability (CVSS 9.1) in Apache IoTDB affects versions 1.0.0 through 1.3.5 and 2.0.0 through 2.0.6. Patch to 1.3.6 or...
The Apache Software Foundation has released urgent security updates for the Apache HTTP Server addressing a severe vulnerability in the HTTP/2 protocol...