Description
** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy.

This issue affects Apache Lucy: all versions.

As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-08-05
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack‑based buffer overflow in the JSON parser error reporter of Apache Lucy. The overflow occurs when processing malformed input, which could allow an attacker to execute arbitrary code with the privileges of the Lucy process. This type of flaw falls under CWE‑121 and directly compromises the confidentiality, integrity, and availability of the system it runs on.

Affected Systems

All versions of Apache Lucy released by the Apache Software Foundation are affected. The project has been retired and is no longer maintained; therefore no patches or updates have been issued.

Risk and Exploitability

The exploitability of this flaw is high because it does not require special user privileges or complex configuration; an attacker can provide malformed JSON data to trigger the overflow. The EPSS score is less than 1%, indicating a low but non‑zero likelihood of exploitation. The CVSS score of 9.8 indicates critical severity. The vulnerability is not listed in the CISA KEV catalog, and the lack of a patch combined with the nature of the stack buffer overflow implies a significant risk. The most likely attack vector is network or local access to the Lucy instance.

Generated by OpenCVE AI on August 5, 2026 at 16:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Discontinue use of Apache Lucy and migrate to a supported alternative that is actively maintained.
  • If migration is not feasible, restrict network access to the Lucy instance so that only trusted users can send requests, using firewall rules, authentication, or VPNs.
  • Continuously monitor logs for attempts to send malformed JSON and block malicious traffic.

Generated by OpenCVE AI on August 5, 2026 at 16:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache lucy
Vendors & Products Apache
Apache lucy

Wed, 05 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Description ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Title Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input
Weaknesses CWE-121
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-05T15:44:15.034Z

Reserved: 2026-07-10T12:23:21.927Z

Link: CVE-2026-61486

cve-icon Vulnrichment

Updated: 2026-08-05T15:44:15.034Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T08:16:35.733

Modified: 2026-08-06T18:38:38.747

Link: CVE-2026-61486

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T16:30:13Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow