<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Apache Spark (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/apache-spark.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/apache-spark-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Apache Spark (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:59 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-54920 – This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54920</guid>
    <pubDate>Mon, 16 Mar 2026 14:17:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54920</strong></p>
  <p>This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue.      Summary  Apache Spark 3.5.4 and earlier versions contain a code execution vulnerability in the Spark History Web UI due to overly permissive Jackson deserialization of event log data. This allows an attacker with access to the Spark event logs…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40195 – Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40195</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40195</guid>
    <pubDate>Mon, 28 Aug 2023 08:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40195</strong></p>
  <p>Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflow Spark Provider.  When the Apache Spark provider is installed on an Airflow deployment, an Airflow user that is authorized to configure Spark hooks can effectively run arbitrary code on the Airflow node by pointing it at a malicious Spark server. Pr…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40195">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32007 – ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to en...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32007</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32007</guid>
    <pubDate>Tue, 02 May 2023 09:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32007</strong></p>
  <p>** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A maliciou…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32007">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-25168 – Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file na...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-25168</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-25168</guid>
    <pubDate>Thu, 04 Aug 2022 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-25168</strong></p>
  <p>Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary commands. This is only used in Hadoop 3.3 InMemoryAliasMap.completeBootstrapTransfer, which is only ever run by a local user. It has been used in Hadoop 2.x for yarn localization, which does enable remote code execution. It is used in Apache Spark,…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25168">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-33891 – The Apache Spark UI offers the possibility to enable ACLs via the configuration ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-33891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-33891</guid>
    <pubDate>Mon, 18 Jul 2022 07:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-33891</strong></p>
  <p>The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to rea…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-33891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-38296 – Apache Spark supports end-to-end encryption of RPC connections via "spark.authen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38296</guid>
    <pubDate>Thu, 10 Mar 2022 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-38296</strong></p>
  <p>Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive attack, this would allow someone to decrypt plaintext traffic offline. Note that this does not affect security mechanism…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-294</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-9480 – In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9480</guid>
    <pubDate>Tue, 23 Jun 2020 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-9480</strong></p>
  <p>In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application's resources on the Spark cluster, even without the shared key. This can be leveraged to execute shell commands on the host machine. This do…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-17190 – In all versions of Apache Spark, its standalone resource manager accepts code to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-17190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-17190</guid>
    <pubDate>Mon, 19 Nov 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-17190</strong></p>
  <p>In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hosts. The master itself does not, by design, execute user code. A specially-crafted request to the master can, however, cause the master to execute code too. Note that this does not affect standalone clusters with authentication enabled. While the mast…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-17190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-12612 – In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserializat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12612</guid>
    <pubDate>Wed, 13 Sep 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-12612</strong></p>
  <p>In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications launched programmatically using the launcher API potentially vulnerable to arbitrary code execution by an attacker with access to any user account on the local machine. It does not affect apps run by spark-submit or spark-shell. The attacker would be able to…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12612">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
