Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4231 articles · 197449 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-61484PATCHED
apache · lucy

Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS

Description

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Affected Products

VendorProductVersions
apachelucy0

References

  • https://lists.apache.org/thread/942t3pwgz2nrhnklrtyt5zr7g4wqc9cb(vendor-advisory)

Related News (2 articles)

Tier C
oss-security20d ago
CVE-2026-61484: Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS
→ No new info (linked only)
Tier C
VulDB20d ago
CVE-2026-61484 | Apache Lucy deserialization
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
*
CWECWE-502
PublishedAug 5, 2026
Trending Score6
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-53434EXP
Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector
Trending: 37
HIGHCVE-2026-57819
Apache CXF: No default restriction on the amount of form parameters per message
Trending: 33
HIGHCVE-2026-54225
Apache CXF: Denial of Service attack via large attachments
Trending: 33
HIGHCVE-2026-64958
Apache CXF: Denial of service via message header attachments
Trending: 33
CRITICALCVE-2026-59084EXP
Apache Tomcat: EncryptInterceptor requirements not clearly documented
Trending: 32

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 5, 2026
Discovered by ZDM
Aug 5, 2026
Patch Available
Aug 5, 2026