Apache Spark
Apache · 17 CVEs
Apache Spark: XSS Vulnerability in Spark Web 3.5.4
Sep 2, 2026
Apache Spark: Spark History Server Code Execution Vulnerability
Mar 14, 2026
Apache Spark, Apache Spark: RPC encryption defaults to unauthenticated AES-CTR mode, enabling man-in-the-middle ciphert…
Oct 15, 2025
Apache Hive, Apache Spark, Apache Spark: CookieSigner exposes the correct signature when message verification fails
Dec 23, 2024
Apache Spark: Shell command injection via Spark UI
May 2, 2023
Apache Spark proxy-user privilege escalation from malicious configuration class
Apr 17, 2023
Apache Spark XSS vulnerability in log viewer UI Javascript
Nov 1, 2022
Apache Spark shell command injection vulnerability via Spark UI
Jul 18, 2022
Apache Spark Key Negotiation Vulnerability
Mar 10, 2022
apache-spark: RCE vulnerability in auth-enabled standalone master
Jun 23, 2020
Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.enc…
Aug 7, 2019
spark: local priviledge escalation when using PySpark
Feb 4, 2019
In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then…
Nov 19, 2018
Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to s…
Oct 24, 2018
spark: Missing authentication allows users to run driver programs via the REST API
Aug 13, 2018
In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointi…
Jul 12, 2018
In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different…
Jul 12, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-32773 | Apache Spark: XSS Vulnerability in Spark Web 3.5.4 | MEDIUM | 0.41% | Sep 2, 2026 |
| CVE-2025-54920 | Apache Spark: Spark History Server Code Execution Vulnerability | HIGH | 5.34% | Mar 14, 2026 |
| CVE-2025-55039 | Apache Spark, Apache Spark: RPC encryption defaults to unauthenticated AES-CTR mode, enabling man-in-the-middle ciphertext modification attacks | LOW | 0.24% | Oct 15, 2025 |
| CVE-2024-23945 | Apache Hive, Apache Spark, Apache Spark: CookieSigner exposes the correct signature when message verification fails | HIGH | 1.56% | Dec 23, 2024 |
| CVE-2023-32007 | Apache Spark: Shell command injection via Spark UI | HIGH | 75.95% | May 2, 2023 |
| CVE-2023-22946 | Apache Spark proxy-user privilege escalation from malicious configuration class | CRITICAL | 1.11% | Apr 17, 2023 |
| CVE-2022-31777 | Apache Spark XSS vulnerability in log viewer UI Javascript | MEDIUM | 1.62% | Nov 1, 2022 |
| CVE-2022-33891 KEV | Apache Spark shell command injection vulnerability via Spark UI | HIGH | 93.24% | Jul 18, 2022 |
| CVE-2021-38296 | Apache Spark Key Negotiation Vulnerability | HIGH | 1.85% | Mar 10, 2022 |
| CVE-2020-9480 | apache-spark: RCE vulnerability in auth-enabled standalone master | CRITICAL | 29.37% | Jun 23, 2020 |
| CVE-2019-10099 | Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true. This includes cach… | HIGH | 1.30% | Aug 7, 2019 |
| CVE-2018-11760 | spark: local priviledge escalation when using PySpark | MEDIUM | 0.60% | Feb 4, 2019 |
| CVE-2018-17190 | In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hosts. The ma… | CRITICAL | 8.79% | Nov 19, 2018 |
| CVE-2018-11804 | Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to speed up compilation. It has been include… | HIGH | 5.70% | Oct 24, 2018 |
| CVE-2018-11770 | spark: Missing authentication allows users to run driver programs via the REST API | MEDIUM | 65.83% | Aug 13, 2018 |
| CVE-2018-8024 | In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and sta… | MEDIUM | 5.29% | Jul 12, 2018 |
| CVE-2018-1334 | In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark appli… | MEDIUM | 0.51% | Jul 12, 2018 |
Showing 1 to 17 of 17 CVEs