CVE Tools

Apache Spark

17 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Apache Spark, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.

Apache Spark CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Apache Spark CVEs per month
MonthCVEs
2024-100
2024-110
2024-121
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-101
2025-110
2025-120
2026-010
2026-020
2026-031
2026-040
2026-050
2026-060
2026-070
2026-080
2026-091

Severity

How the 17 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical212%
  • High635%
  • Medium953%

Latest CVEs

The 15 most recently published vulnerabilities affecting Apache Spark.

  1. CVE-2026-32773Apache Spark: XSS Vulnerability in Spark Web 3.5.46.1
  2. CVE-2025-54920Apache Spark: Spark History Server Code Execution Vulnerability8.8
  3. CVE-2025-55039Apache Spark, Apache Spark: RPC encryption defaults to unauthenticated AES-CTR mode, enabling man-in-the-middle ciphertext modification attacks6.5
  4. CVE-2024-23945Apache Hive, Apache Spark, Apache Spark: CookieSigner exposes the correct signature when message verification fails5.9
  5. CVE-2023-32007Apache Spark: Shell command injection via Spark UI8.8
  6. CVE-2023-22946Apache Spark proxy-user privilege escalation from malicious configuration class6.4
  7. CVE-2022-31777Apache Spark XSS vulnerability in log viewer UI Javascript5.4
  8. CVE-2022-33891Apache Spark shell command injection vulnerability via Spark UI8.8
  9. CVE-2021-38296Apache Spark Key Negotiation Vulnerability7.5
  10. CVE-2020-9480In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-cr...9.8
  11. CVE-2019-10099Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true. This includes cached blocks that are fetched to disk (co...7.5
  12. CVE-2018-11760When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2....5.5
  13. CVE-2018-17190In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hosts. The master itself does not, by design, execu...9.8
  14. CVE-2018-11804Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to speed up compilation. It has been included in release branches since 1.3.x, up ...7.5
  15. CVE-2018-11770From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit. In standalone, the config property '...4.2

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store