Apache Project Security Information
Security information for individual Apache projects
Here is a list of pages ASF projects maintain to provide information on known security vulnerabilities. Each entry also has the security contact for reporting new vulnerabilities related to that project. Note that not all project security teams have a dedicated address for reporting new vulnerabilities.
To report a vulnerability in an Apache project that is not listed below, contact the Apache Security Team.
Use the tabs below to jump to projects by their initial. Every project lists a security contact; some also publish a security page and a list of advisories.
A
Apache Accumulo
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org
- Security contact:
Apache ActiveMQ
- Security contact:
security@apache.org - Advisories:
activemq.apache.org - Security model:
- Security contact:
Apache AGE
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org
- Security contact:
Apache Airavata
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org
- Security contact:
Apache Airflow
- Security contact:
security@airflow.apache.org - Advisories (experimental):
security.apache.org - Security model:
- Security contact:
Apache Allura
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org - Security model:
- Security contact:
Apache Ambari
- Security contact:
security@ambari.apache.org - Advisories (experimental):
security.apache.org
- Security contact:
Apache Amoro (Incubating)
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
Apache Answer
- Security contact:
security@apache.org - Advisories:
answer.apache.org - Security model:
- Security contact:
Apache Ant
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org - Security model:
- Security contact:
Apache APISIX
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org - Security model:
- Security contact:
Apache Aries
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
Apache Arrow
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org - Security model:
- Security contact:
- Apache Artemis
- Security contact:
security@apache.org - Advisories:
artemis.apache.org - Security model:
- Security contact:
Apache AsterixDB
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org
- Security contact:
- Apache Asyncband (Incubating)
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
Apache Atlas
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org
- Security contact:
Apache Auron (Incubating)
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
Apache Avro
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org - Security model:
- Security contact:
- Apache Axis
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org - Security models:
- Security contact:
B
Apache Beam
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
- Apache BifroMQ (Incubating)
- Security contact:
security@apache.org - Advisories (experimental):
none so far - Security model:
- Security contact:
Apache Bigtop
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
Apache BookKeeper
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org
- Security contact:
Apache Brooklyn
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
Apache bRPC
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org - Security model:
- Security contact:
- Apache BuildStream
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
- Apache Burr (Incubating)
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
Apache BVal
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
C
Apache Calcite
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org - Security model:
- Security contact:
- Apache Caldera (Incubating)
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
Apache Camel
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org - Security models:
- Security contact:
Apache Carbondata
- Security contact:
security@apache.org - Advisories (experimental):
none so far - Security model:
- Security contact:
Apache Casbin (Incubating)
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
Apache Cassandra
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org - Security model:
- Security contact:
Apache Causeway
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org
- Security contact:
Apache Cayenne
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org
- Security contact:
Apache Celeborn
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
Apache Celix
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
Apache Cloudberry (Incubating)
- Security contact:
security@apache.org - Advisories (experimental):
none so far - Security model:
- Security contact:
Apache CloudStack
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org - Security model:
- Security contact:
Apache Commons
- Security contact:
security@commons.apache.org - Advisories:
commons.apache.org - Security models:
- Security contact:
Apache Cordova
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org
- Security contact:
Apache CouchDB
- Security contact:
security@couchdb.apache.org - Advisories (experimental):
security.apache.org
- Security contact:
Apache Creadur
- Security contact:
security@apache.org - Advisories (experimental):
none so far - Security model:
- Security contact:
Apache cTAKES
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
Apache Curator
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
Apache CXF
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org - Security models:
- Security contact:
D
Apache Daffodil
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
Apache DataFu
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
- Apache DataFusion
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
Apache DataSketches
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
Apache DB
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org - Security model:
- Security contact:
Apache DeltaSpike
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
Apache DevLake
- Security contact:
security@apache.org - Advisories (experimental):
none so far - Security model:
- Security contact:
Apache Directory
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org - Security models:
- Security contact:
Apache DolphinScheduler
- Security contact:
security@dolphinscheduler.apache.org - Advisories (experimental):
security.apache.org - Security model:
- Security contact:
Apache Doris
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org - Security model:
- Security contact:
Apache Drill
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org - Security model:
- Security contact:
Apache Druid
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org - Security model:
- Security contact:
Apache Dubbo
- Security contact:
security@dubbo.apache.org - Advisories (experimental):
security.apache.org - Security model:
- Security contact:
E
Apache ECharts
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org - Security model:
- Security contact:
- Apache Empire-db
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
Apache EventMesh
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org
- Security contact:
F
Apache Felix
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org
- Security contact:
Apache Fesod (Incubating)
- Security contact:
security@apache.org - Advisories (experimental):
security.apache.org
- Security contact:
Apache Fineract
- Security contact:
security@fineract.apache.org - Advisories:
fineract.apache.org - Security model:
- Security contact:
Apache Flagon
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
Apache Flex
- Security contact:
security@apache.org - Advisories (experimental):
none so far
- Security contact:
Apache Flink
- Security contact:
security@apache.org - Advisories:
flink.apache.org
- Security contact: