Deserialization of Untrusted Data Vulnerability in Apache Lucy by Apache
CVE-2026-61484

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
5 August 2026

What is CVE-2026-61484?

A deserialization of untrusted data vulnerability has been identified in Apache Lucy, impacting all versions of the project. This issue arises due to the handling of untrusted data, which can potentially lead to unauthorized actions or exposure of sensitive information. However, since Apache Lucy has been retired and is no longer maintained, users are advised to seek alternative solutions or limit access to their instances to trusted users only. Without an official fix, the risk remains significant for those still utilizing this software.

Affected Version(s)

Apache Lucy 0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.