VendorsApachelucyall versions
Vulnerabilities

Apache Software Foundation Lucy

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2026-61486
Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input
Published 2026-08-05 · Modified
9.8EPSS 0.008
CVE-2026-61484
Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS
Published 2026-08-05 · Modified
9.8EPSS 0.008
CVE-2026-61483
Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow DoS
Published 2026-08-05 · Modified
7.5EPSS 0.010
CVE-2026-61485
Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index
Published 2026-08-05 · Rejected
n/aEPSS 0.006