Apache Software Foundation Apache Lucy vulnerabilities
4 known vulnerabilities affecting apache_software_foundation/apache_lucy.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2
Vulnerabilities
Page 1 of 1
CVE-2026-61484P2CRITICALCVSS 9.8fixed in 0.8.02026-08-05
CVE-2026-61484 [CRITICAL] CWE-502 CVE-2026-61484: ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. T
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy.
This issue affects Apache Lucy: all versions.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
Lucy is now maintai
nvd
CVE-2026-61486P2CRITICALCVSS 9.8fixed in 0.8.02026-08-05
CVE-2026-61486 [CRITICAL] CWE-121 CVE-2026-61486: ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This is
** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy.
This issue affects Apache Lucy: all versions.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
Lucy is now maintained ou
nvd
CVE-2026-61483P3HIGHCVSS 7.5fixed in 0.8.02026-08-05
CVE-2026-61483 [HIGH] CWE-674 CVE-2026-61483: ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue a
** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy.
This issue affects Apache Lucy: all versions.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
NOTE: This vulnerability only affe
nvd
CVE-2026-61485P3HIGHCVSS 7.5≤ *2026-08-05
CVE-2026-61485 [HIGH] CWE-789 CVE-2026-61485: ** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache
** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy.
This issue affects Apache Lucy: all versions.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
NOTE: This vul
nvd