Apache Spark History Server allows stored cross-site scripting through unescaped application names
Medium6.1CVE-2026-32773 · Published Sep 2, 2026 · updated Oct 5, 2026
There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later. This CVE is marked as "low" since the path to exploit requires both relatively high permissions (ability to launch a Spark job) and requires tricking a user with higher permissions to log in and visit the Spark history web page. Users are encouraged to upgrade their Spark history servers to Spark 3.5.8 or later.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.spark:spark-core_2.12 Maven | >= 3.0.0, < 3.5.8 | 3.5.8 |
| org.apache.spark:spark-core_2.13 Maven | >= 3.0.0, < 3.5.8 | 3.5.8 |
| pyspark PyPI | >= 3.0.0, < 3.5.8 | 3.5.8 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-80
- Also known as
- BIT-spark-2026-32773, CVE-2026-32773, PYSEC-2026-3966
- nvd.nist.gov/vuln/detail/CVE-2026-32773
- github.com/apache/spark/pull/52851
- github.com/apache/spark/commit/3c83c2c6a22fe384280b99bb753b14800b7e27e1
- github.com/apache/spark/commit/e739b7d349dbd41b78d49bc8086cab63db057e14
- github.com/apache/spark
- github.com/pypa/advisory-database/tree/main/vulns/pyspark/PYSEC-2026-3966.yaml
- issues.apache.org/jira/browse/SPARK-53747
- lists.apache.org/thread/k36prh3oxl1z6ov7w8rpmfnt07hmzw3v
- www.openwall.com/lists/oss-security/2026/09/01/4
More Apache Spark advisories
All Apache Spark| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 2 | Apache Spark: cross-site scripting | Medium6.1 | 3.5.8 |
| Mar 16 | Apache Spark: Spark History Server Code Execution Vulnerability | High8.8 | 3.5.7+1 more |
| Oct 152025 | Apache Spark has Inadequate Encryption Strength | Low | 3.4.4+1 more |
| May 22023 | Apache Spark UI vulnerable to Command Injection | High8.8 | 3.2.2 |
| Apr 172023 | Apache Spark vulnerable to Improper Privilege Management | Critical9.9 | 3.3.2+1 more |
| Nov 12022 | Apache Spark vulnerable to Log Injection | Medium5.4 | 3.2.2+1 more |