« Back to list

Apache

Apache Spark: vulnerabilities and CVEs

Apache Spark has 24 published vulnerabilities, 4 of them in the last 12 months. 4 are rated critical and 1 are listed by CISA as actively exploited.

CVEs24
Last 12 months4
Critical4
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2022-33891High (8.8)93%⚠ Active exploitationJul 18, 2022
The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-32773Medium (6.1)0.68%—Sep 2, 2026
There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser.…
CVE-2026-18428High (8.7)1.00%—Aug 13, 2026
A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a…
CVE-2025-54920High (8.8)5.3%—Mar 16, 2026
This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summary Apache Spark 3.5.4 and earlier versions contain a code…
CVE-2025-55039Medium (6.5)0.24%—Oct 15, 2025
This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure default network encryption cipher for RPC communication between nodes. When…
CVE-2024-23945Medium (5.9)1.6%—Dec 23, 2024
Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signature helps prevent malicious actors from modifying the cookie value,…
CVE-2023-32007High (8.8)76%—May 2, 2023
** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions…
CVE-2023-22946Critical (9.9)1.1%—Apr 17, 2023
In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application can execute code with the privileges of the submitting user, however,…
CVE-2022-31777Medium (5.4)1.6%—Nov 1, 2022
A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into…
CVE-2022-33891High (8.8)93%⚠ Active exploitationJul 18, 2022
The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the…
CVE-2021-38296High (7.5)1.8%—Mar 10, 2022
Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for…
CVE-2020-27223Medium (5.3)78%—Feb 26, 2021
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may…
CVE-2020-27218Medium (4.8)8.3%—Nov 28, 2020
In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed…
CVE-2020-9480Critical (9.8)29%—Jun 23, 2020
In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the…
CVE-2019-20445Critical (9.1)13%—Jan 29, 2020
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
CVE-2019-10172High (7.5)17%—Nov 18, 2019
A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.
CVE-2019-10099High (7.5)1.3%—Aug 7, 2019
Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true. This includes cached blocks that are fetched to disk (controlled by…
CVE-2018-11760Medium (5.5)0.60%—Feb 4, 2019
When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and…
CVE-2018-17190Critical (9.8)8.8%—Nov 19, 2018
In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hosts. The master itself does not, by design, execute user code. A…
CVE-2018-11804High (7.5)5.7%—Oct 24, 2018
Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to speed up compilation. It has been included in release branches since 1.3.x, up to and including…
CVE-2018-11770Medium (4.2)66%—Aug 13, 2018
From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit. In standalone, the config property…
CVE-2018-8024Medium (5.4)5.3%—Jul 12, 2018
In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing…
CVE-2018-1334Medium (4.7)0.51%—Jul 12, 2018
In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark…
CVE-2017-12612High (7.8)0.73%—Sep 13, 2017
In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications launched programmatically using the launcher API potentially vulnerable to…
CVE-2017-7678Medium (6.1)3.4%—Jul 12, 2017
In Apache Spark before 2.2.0, it is possible for an attacker to take advantage of a user's trust in the server to trick them into visiting a link that points to a shared Spark cluster and submits data including MHTML to…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter3
  2. T1210 Exploitation of Remote Services3

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

📰 Related news

Other products by Apache