Skip to content
Apache SparkGHSA-9437-39hj-3c93

Apache Spark History Server allows stored cross-site scripting through unescaped application names

Medium6.1CVE-2026-32773 · Published Sep 2, 2026 · updated Oct 5, 2026

There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later. This CVE is marked as "low" since the path to exploit requires both relatively high permissions (ability to launch a Spark job) and requires tricking a user with higher permissions to log in and visit the Spark history web page. Users are encouraged to upgrade their Spark history servers to Spark 3.5.8 or later.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.spark:spark-core_2.12
Maven
>= 3.0.0, < 3.5.83.5.8
org.apache.spark:spark-core_2.13
Maven
>= 3.0.0, < 3.5.83.5.8
pyspark
PyPI
>= 3.0.0, < 3.5.83.5.8
Details and references

More Apache Spark advisories

All Apache Spark
Advisory
Apache Spark: cross-site scripting
Medium6.1Sep 2
Apache Spark: Spark History Server Code Execution Vulnerability
High8.8Mar 16
Apache Spark has Inadequate Encryption Strength
LowOct 15, 2025
Apache Spark UI vulnerable to Command Injection
High8.8May 2, 2023
Apache Spark vulnerable to Improper Privilege Management
Critical9.9Apr 17, 2023
Apache Spark vulnerable to Log Injection
Medium5.4Nov 1, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.