7.5
CVE-2026-61485
- EPSS 0.52%
- Veröffentlicht 05.08.2026 06:43:27
- Zuletzt bearbeitet 06.08.2026 18:38:47
- CVE-Watchlists
- Unerledigt
Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index
** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.52% | 0.415 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-789 Memory Allocation with Excessive Size Value
The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
https://lists.apache.org/thread/4q9rfscp3tkjr3kt7lsg97szhmydl23s
http://www.openwall.com/lists/oss-security/2026/08/05/6