Description
** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy.

This issue affects Apache Lucy: all versions.

As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-08-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack‑based buffer overflow in the JSON parser error reporter of Apache Lucy. The overflow occurs when processing malformed input, which could allow an attacker to execute arbitrary code with the privileges of the Lucy process. This type of flaw falls under CWE‑121 and directly compromises the confidentiality, integrity, and availability of the system it runs on.

Affected Systems

All versions of Apache Lucy released by the Apache Software Foundation are affected. The project has been retired and is no longer maintained; therefore no patches or updates have been issued.

Risk and Exploitability

The exploitability of this flaw is high because it does not require special user privileges or complex configuration; an attacker can provide malformed JSON data to trigger the overflow. No EPSS score is available, but the lack of a patch and the nature of the stack buffer overflow imply a significant risk. The vulnerability is not listed in the CISA KEV catalog, and no CVSS score is provided, so the exact severity rating cannot be quoted. The most likely attack vector is network or local access to the Lucy instance.

Generated by OpenCVE AI on August 5, 2026 at 08:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Discontinue use of Apache Lucy and migrate to a supported alternative that is actively maintained.
  • If migration is not feasible, restrict network access to the Lucy instance so that only trusted users can send requests, using firewall rules, authentication, or VPNs.
  • Continuously monitor logs for attempts to send malformed JSON and block malicious traffic.

Generated by OpenCVE AI on August 5, 2026 at 08:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Description ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Title Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input
Weaknesses CWE-121
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-05T06:44:11.537Z

Reserved: 2026-07-10T12:23:21.927Z

Link: CVE-2026-61486

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T08:30:04Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow