Skip to content
Apache SupersetGHSA-cpvx-2365-466c

Apache Superset may expose internal traces on REST API endpoints

Medium4.3CVE-2023-39264 · Published Sep 6, 2023 · updated Jul 7, 2026

By default, stack traces for errors were enabled, which resulted in the exposure of internal traces on REST API endpoints to users. This vulnerability exists in Apache Superset versions up to and including 2.1.0.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
<= 2.1.0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-209
Also known as
BIT-superset-2023-39264, CVE-2023-39264, PYSEC-2026-1172

More Apache Superset advisories

All Apache Superset
Advisory
Apache Superset has incorrect authorization check
Medium4.3Sep 6, 2023
Apache Superset Deserialization of Untrusted Data vulnerability
Medium6.6Sep 6, 2023
Apache Superset Improper Input Validation vulnerability
Medium6.5Sep 6, 2023
Apache Superset Server Side Request Forgery vulnerability
Medium4.3Sep 6, 2023
Apache Superset has improper default REST API permission for Gamma users
Medium5.4Sep 6, 2023
Apache Superset users may incorrectly create resources using the import charts feature
Medium4.3Sep 6, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.