CVE Tools

Spark

36 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Spark, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Spark CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Spark CVEs per month
MonthCVEs
2024-100
2024-110
2024-121
2025-010
2025-020
2025-030
2025-041
2025-050
2025-060
2025-070
2025-080
2025-090
2025-101
2025-110
2025-120
2026-010
2026-021
2026-031
2026-040
2026-050
2026-060
2026-071
2026-080
2026-091

Severity

How the 36 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical38%
  • High1131%
  • Medium2158%
  • Low13%

Latest CVEs

The 15 most recently published vulnerabilities affecting Spark.

  1. CVE-2026-32773Apache Spark: XSS Vulnerability in Spark Web 3.5.46.1
  2. CVE-2026-17459perwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink4.3
  3. CVE-2025-54920Apache Spark: Spark History Server Code Execution Vulnerability8.8
  4. CVE-2026-1743DJI Mavic Mini/Air/Spark/Mini SE Enhanced Wi-Fi Pairing authentication replay3.1
  5. CVE-2025-55039Apache Spark, Apache Spark: RPC encryption defaults to unauthenticated AES-CTR mode, enabling man-in-the-middle ciphertext modification attacks6.5
  6. CVE-2025-3518File upload functionality possible even when disabled4.3
  7. CVE-2024-23945Apache Hive, Apache Spark, Apache Spark: CookieSigner exposes the correct signature when message verification fails5.9
  8. CVE-2023-32007Apache Spark: Shell command injection via Spark UI8.8
  9. CVE-2023-22946Apache Spark proxy-user privilege escalation from malicious configuration class6.4
  10. CVE-2022-31777Apache Spark XSS vulnerability in log viewer UI Javascript5.4
  11. CVE-2022-33891Apache Spark shell command injection vulnerability via Spark UI8.8
  12. CVE-2021-38296Apache Spark Key Negotiation Vulnerability7.5
  13. CVE-2021-32054Firely/Incendi Spark before 1.5.5-r4 lacks Content-Disposition headers in certain situations, which may cause crafted files to be delivered to clients such that they are rendered directly in a vict...6.1
  14. CVE-2020-27223In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) pa...5.2
  15. CVE-2020-27218In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clien...4.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store