Apache Spark
17 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Apache Spark, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
Apache Spark CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 1 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 1 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 1 |
Severity
How the 17 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High6
- Medium9
Latest CVEs
The 15 most recently published vulnerabilities affecting Apache Spark.
- CVE-2026-32773Apache Spark: XSS Vulnerability in Spark Web 3.5.46.1
- CVE-2025-54920Apache Spark: Spark History Server Code Execution Vulnerability8.8
- CVE-2025-55039Apache Spark, Apache Spark: RPC encryption defaults to unauthenticated AES-CTR mode, enabling man-in-the-middle ciphertext modification attacks6.5
- CVE-2024-23945Apache Hive, Apache Spark, Apache Spark: CookieSigner exposes the correct signature when message verification fails5.9
- CVE-2023-32007Apache Spark: Shell command injection via Spark UI8.8
- CVE-2023-22946Apache Spark proxy-user privilege escalation from malicious configuration class6.4
- CVE-2022-31777Apache Spark XSS vulnerability in log viewer UI Javascript5.4
- CVE-2022-33891Apache Spark shell command injection vulnerability via Spark UI8.8
- CVE-2021-38296Apache Spark Key Negotiation Vulnerability7.5
- CVE-2020-9480In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-cr...9.8
- CVE-2019-10099Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true. This includes cached blocks that are fetched to disk (co...7.5
- CVE-2018-11760When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2....5.5
- CVE-2018-17190In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hosts. The master itself does not, by design, execu...9.8
- CVE-2018-11804Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to speed up compilation. It has been included in release branches since 1.3.x, up ...7.5
- CVE-2018-11770From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit. In standalone, the config property '...4.2
Product grouping is registry-driven, with AI assist and human review. How it works