Description
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy.

This issue affects Apache Lucy: all versions.

As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-08-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An untrusted data deserialization flaw exists in Apache Lucy that allows an attacker to send a specially crafted Storable::thaw payload to the LucyX::Remote::SearchServer endpoint. This flaw can be leveraged to execute arbitrary code or trigger a denial of service. The flaw is present in all versions of Lucy, and because the project has been retired, no vendor patch will be released. Users must therefore secure the component or migrate away.

Affected Systems

The affected product is Apache Lucy developed by the Apache Software Foundation. All released versions of Lucy are impacted. The project is currently retired and will not receive updates.

Risk and Exploitability

The attack vector is remote and unauthenticated, meaning that anyone who can reach the SearchServer interface can exploit the flaw. The absence of a public patch and the project's retirement elevate the risk. While no EPSS score is published and the vulnerability is not listed in the KEV catalog, the potential for remote code execution implies a high severity. Mitigation requires restricting access or replacing the software altogether.

Generated by OpenCVE AI on August 5, 2026 at 08:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or remove the Apache Lucy SearchServer from production systems.
  • Configure network or application controls to limit access to the SearchServer endpoint to trusted IP addresses only.
  • Migrate application data and functionality to a modern, actively maintained search platform such as Elasticsearch or Apache Solr.

Generated by OpenCVE AI on August 5, 2026 at 08:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Description ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Title Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS
Weaknesses CWE-502
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-05T06:42:06.543Z

Reserved: 2026-07-10T12:23:21.927Z

Link: CVE-2026-61484

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T08:30:04Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data