Skip to content

Apache Spark security advisories

13 advisories · 1 critical or high in 12 months · latest Sep 2

13 advisories

DateAdvisory
Sep 2There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later.
CVE-2026-32773Medium6.1fixed in 3.5.8
Mar 16Apache Spark: Spark History Server Code Execution Vulnerability
CVE-2025-54920High8.8fixed in 3.5.7, 4.0.1
Oct 152025Apache Spark has Inadequate Encryption Strength
CVE-2025-55039Lowfixed in 3.4.4, 3.5.2
May 22023Apache Spark UI vulnerable to Command Injection
CVE-2023-32007High8.8fixed in 3.2.2
Apr 172023Apache Spark vulnerable to Improper Privilege Management
CVE-2023-22946Critical9.9fixed in 3.3.2, 3.3.3
Nov 12022Apache Spark vulnerable to Log Injection
CVE-2022-31777Medium5.4fixed in 3.2.2, 3.3.1
Jul 192022Apache Spark UI can allow impersonation if ACLs enabled
CVE-2022-33891High8.8fixed in 3.1.3, 3.2.2
Mar 112022Authentication Bypass by Capture-replay in Apache Spark
CVE-2021-38296High7.5fixed in 3.1.3
Feb 102022Improper Authentication in Apache Spark
CVE-2020-9480Critical9.8fixed in 2.4.6
Aug 82019Sensitive data written to disk unencrypted in Spark
CVE-2019-10099High7.5fixed in 2.3.3
Mar 142019Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark
CVE-2018-1334Medium4.7fixed in 2.1.3, 2.2.2
Feb 72019Pyspark User Impersonation Vulnerability
CVE-2018-11760Medium5.5fixed in 2.2.3, 2.3.2
Nov 92018Apache Spark Deserialization of Untrusted Data vulnerability
CVE-2017-12612High7.8fixed in 2.1.2
About Apache Spark

The engine for large-scale data processing.

Packages watched: pyspark (PyPI), org.apache.spark:spark-core_2.13 (Maven), org.apache.spark:spark-core_2.12 (Maven).

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.