Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2806 articles · 108988 vulns · 38/41 feeds (7d)
← Back to list
—
CVE-2026-32588PATCHED
apache software foundation · apache cassandra

Apache Cassandra: Authenticated DoS via ALTER ROLE Password Hashing

Description

Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes. Users are recommended to upgrade to version 4.0.20, 4.1.11, 5.0.7, which fixes this issue.

Affected Products

VendorProductVersions
apache software foundationapache cassandramaven/org.apache.cassandra:cassandra-all: >= 4.0, < 4.0.20, maven/org.apache.cassandra:cassandra-all: >= 4.1, < 4.1.11, maven/org.apache.cassandra:cassandra-all: >= 5.0, < 5.0.7

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
mavenorg.apache.cassandra:cassandra-allGHSA85%

References

  • https://lists.apache.org/thread/2tnwjdnss378glxrsmnlzz3k53ftphrc(vendor-advisory)

Related News (2 articles)

Tier C
oss-security1d ago
CASSANDRA-21202: CVE-2026-32588: Apache Cassandra: Authenticated DoS via ALTER ROLE Password Hashing
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-32588 | Apache Cassandra up to 4.0.19/4.1.10/5.0.6 ALTER ROLE Password denial of service
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
org.apache.cassandra:cassandra-all@4.0.20org.apache.cassandra:cassandra-all@4.1.11org.apache.cassandra:cassandra-all@5.0.7
CWECWE-400
PublishedApr 7, 2026
Trending Score29
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-34197EXP
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
Trending: 77
HIGHCVE-2026-27314EXP
Apache Cassandra: Privilege escalation via ADD IDENTITY authorization bypass
Trending: 63
HIGHCVE-2026-35554
Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition
Trending: 40
MEDIUMCVE-2026-27315
Apache Cassandra: cqlsh history sensitive information leak
Trending: 31
MEDIUMCVE-2026-33227
Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ: Improper Limitation of a Pathname to a Restricted Classpath Directory
Trending: 29

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 7, 2026
Discovered by ZDM
Apr 7, 2026
Patch Available
Apr 7, 2026