Apache Spark

2 known vulnerabilities in Apache Spark, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2022-33891 CVSS 8.8 high · actively exploited Apache Spark Command Injection Vulnerability

Latest vulnerabilities

  • CVE-2026-32773 CVSS 6.1 medium There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary…
  • CVE-2022-33891 CVSS 8.8 high · actively exploited Apache Spark Command Injection Vulnerability