Spark
36 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Spark, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Spark CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 1 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 1 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 1 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 1 |
| 2026-03 | 1 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 1 |
| 2026-08 | 0 |
| 2026-09 | 1 |
Severity
How the 36 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High11
- Medium21
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Spark.
- CVE-2026-32773Apache Spark: XSS Vulnerability in Spark Web 3.5.46.1
- CVE-2026-17459perwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink4.3
- CVE-2025-54920Apache Spark: Spark History Server Code Execution Vulnerability8.8
- CVE-2026-1743DJI Mavic Mini/Air/Spark/Mini SE Enhanced Wi-Fi Pairing authentication replay3.1
- CVE-2025-55039Apache Spark, Apache Spark: RPC encryption defaults to unauthenticated AES-CTR mode, enabling man-in-the-middle ciphertext modification attacks6.5
- CVE-2025-3518File upload functionality possible even when disabled4.3
- CVE-2024-23945Apache Hive, Apache Spark, Apache Spark: CookieSigner exposes the correct signature when message verification fails5.9
- CVE-2023-32007Apache Spark: Shell command injection via Spark UI8.8
- CVE-2023-22946Apache Spark proxy-user privilege escalation from malicious configuration class6.4
- CVE-2022-31777Apache Spark XSS vulnerability in log viewer UI Javascript5.4
- CVE-2022-33891Apache Spark shell command injection vulnerability via Spark UI8.8
- CVE-2021-38296Apache Spark Key Negotiation Vulnerability7.5
- CVE-2021-32054Firely/Incendi Spark before 1.5.5-r4 lacks Content-Disposition headers in certain situations, which may cause crafted files to be delivered to clients such that they are rendered directly in a vict...6.1
- CVE-2020-27223In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) pa...5.2
- CVE-2020-27218In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clien...4.8
Product grouping is registry-driven, with AI assist and human review. How it works