Impact
An untrusted data deserialization flaw exists in Apache Lucy that allows an attacker to send a specially crafted Storable::thaw payload to the LucyX::Remote::SearchServer endpoint. The flaw can be leveraged to execute arbitrary code or trigger a denial of service. Because the project has been retired, no vendor patch will be released, leaving affected deployments without an official fix.
Affected Systems
The affected product is Apache Lucy developed by the Apache Software Foundation. All versions of Lucy that are no longer supported, including those prior to 0.8.0, are impacted. Version 0.8.0 and later have removed the offending feature and are not affected. The project is currently retired and will not receive updates.
Risk and Exploitability
Based on the description, it is inferred that the attack vector is remote and unauthenticated, meaning that anyone who can reach the SearchServer interface can exploit the flaw. The CVSS score of 9.8 denotes critical severity, while the EPSS score of <1% suggests a low probability of exploitation in the wild. Since the vulnerability is not listed in CISA KEV and the software is retired, the risk remains high. No public patch exists, so mitigating actions such as restricting access or replacing the software remain the only effective measures.
OpenCVE Enrichment