Apache Software Foundation Apache Ant vulnerabilities
3 known vulnerabilities affecting apache_software_foundation/apache_ant.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-78254P3HIGHCVSS 7.4≥ 1.2, < 1.10.182026-09-07
CVE-2026-78254 [HIGH] CWE-23 CVE-2026-78254: The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can
The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the permissions of the user running Ant in versions prior to Ant 1.10.18.
In o
nvd
CVE-2021-36374P4MEDIUMCVSS 5.5≥ 1.4, < Apache Ant*≥ Apache Ant 1.9.x, ≤ 1.9.15+1 more2021-07-14
CVE-2021-36374 [MEDIUM] CWE-130 CVE-2021-36374: When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apac
nvd
CVE-2021-36373P4MEDIUMCVSS 5.5≥ Apache Ant 1.9.x, ≤ 1.9.15≥ Apache Ant 1.10.x, ≤ 1.10.102021-07-14
CVE-2021-36373 [MEDIUM] CWE-130 CVE-2021-36373: When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amoun
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
nvd