Description
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy.

This issue affects Apache Lucy: all versions.

As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-08-05
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An untrusted data deserialization flaw exists in Apache Lucy that allows an attacker to send a specially crafted Storable::thaw payload to the LucyX::Remote::SearchServer endpoint. This flaw can be leveraged to execute arbitrary code or trigger a denial of service. The flaw is present in all versions of Lucy, and because the project has been retired, no vendor patch will be released. Users must therefore secure the component or migrate away.

Affected Systems

The affected product is Apache Lucy developed by the Apache Software Foundation. All released versions of Lucy are impacted. The project is currently retired and will not receive updates.

Risk and Exploitability

The attack vector is remote and unauthenticated, meaning that anyone who can reach the SearchServer interface can exploit the flaw. The absence of a public patch and the project's retirement elevate the risk. The CVSS score of 9.8 underscores a critical severity, while the EPSS score of <1% suggests a low probability of exploitation in the wild. Because the vulnerability is not listed in CISA KEV and no vendor patch exists, mitigating actions such as restricting access or replacing the software remain the only effective measures.

Generated by OpenCVE AI on August 5, 2026 at 16:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or remove the Apache Lucy SearchServer from production systems.
  • Configure network or application controls to limit access to the SearchServer endpoint to trusted IP addresses only.
  • Migrate application data and functionality to a modern, actively maintained search platform such as Elasticsearch or Apache Solr.

Generated by OpenCVE AI on August 5, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache lucy
Vendors & Products Apache
Apache lucy

Wed, 05 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Description ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Title Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS
Weaknesses CWE-502
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-05T15:44:12.718Z

Reserved: 2026-07-10T12:23:21.927Z

Link: CVE-2026-61484

cve-icon Vulnrichment

Updated: 2026-08-05T15:44:12.718Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T08:16:35.487

Modified: 2026-08-06T18:38:53.463

Link: CVE-2026-61484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T16:30:13Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data