Apache Spark
Apache Software Foundation- Product type
- Other
- Catalog vulnerabilities
- 16
Severity across 16 analyzed records
Verify to analyze this security profile
en
Severity across 16 analyzed records
Verify to analyze this security profile
As of 09/15/2026, within CyStack's analyzed data, Apache Spark has 1 security vulnerability published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Apache Spark and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-32773Apache Spark: XSS Vulnerability in Spark Web 3.5.4 | Exploitation statusNot known exploited | FixYes | Published09/02/2026 | SeverityMedium |
CVE-2025-54920Apache Spark: Spark History Server Code Execution Vulnerability | Exploitation statusNot known exploited | FixYes | Published03/14/2026 | SeverityHigh |
CVE-2025-55039Apache Spark, Apache Spark: RPC encryption defaults to unauthenticated AES-CTR mode, enabling man-in-the-middle ciphertext modification attacks | Exploitation statusNot known exploited | FixYes | Published10/15/2025 | SeverityMedium |
CVE-2024-23945Apache Hive, Apache Spark, Apache Spark: CookieSigner exposes the correct signature when message verification fails | Exploitation statusNot known exploited | FixYes | Published12/23/2024 | SeverityMedium |
CVE-2023-32007Apache Spark: Shell command injection via Spark UI | Exploitation statusNot known exploited | FixYes | Published05/02/2023 | SeverityHigh |
CVE-2023-22946Apache Spark proxy-user privilege escalation from malicious configuration class | Exploitation statusNot known exploited | FixYes | Published04/17/2023 | SeverityMedium |
CVE-2022-31777Apache Spark XSS vulnerability in log viewer UI Javascript | Exploitation statusNot known exploited | FixNot confirmed | Published11/01/2022 | SeverityMedium |
CVE-2022-33891Apache Spark shell command injection vulnerability via Spark UI | Exploitation statusKEV | FixNot confirmed | Published07/18/2022 | SeverityHigh |
CVE-2021-38296Apache Spark Key Negotiation Vulnerability | Exploitation statusNot confirmed | FixNot confirmed | Published03/10/2022 | SeverityUnknown |
CVE-2020-9480 | Exploitation statusNot confirmed | FixNot confirmed | Published06/23/2020 | SeverityUnknown |
CVE-2018-11760 | Exploitation statusNot confirmed | FixNot confirmed | Published02/04/2019 | SeverityUnknown |
CVE-2018-17190 | Exploitation statusNot confirmed | FixNot confirmed | Published11/19/2018 | SeverityUnknown |
CVE-2018-11804 | Exploitation statusNot confirmed | FixYes | Published10/24/2018 | SeverityUnknown |
CVE-2018-11770 | Exploitation statusNot confirmed | FixYes | Published08/13/2018 | SeverityUnknown |
CVE-2018-8024 | Exploitation statusNot confirmed | FixNot confirmed | Published07/12/2018 | SeverityUnknown |
CVE-2018-1334 | Exploitation statusNot confirmed | FixNot confirmed | Published07/12/2018 | SeverityUnknown |