Known Vulnerabilities for Spark by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Spark" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-44182 json | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes... | Not Provided | 2026-07-16 | 2026-07-17 |
| CVE-2026-44181 json | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes... | Not Provided | 2026-07-16 | 2026-07-17 |
| CVE-2026-44180 json | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes... | Not Provided | 2026-07-16 | 2026-07-17 |
| CVE-2026-15183 json | Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can allo... | Not Provided | 2026-07-14 | 2026-07-14 |
| CVE-2026-8326 json | Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary fi... | Not Provided | 2026-05-29 | 2026-05-29 |
| CVE-2026-8152 json | Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack. ... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-6213 json | A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and a... | Not Provided | 2026-05-08 | 2026-05-08 |
| CVE-2023-32007 json | ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.... | 8.8 - HIGH | 2023-05-02 | 2023-05-10 |
| CVE-2023-22946 json | In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privi... | 9.9 - CRITICAL | 2023-04-17 | 2023-04-26 |
| CVE-2022-33891 json | The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authenticat... | 8.8 - HIGH | 2022-07-18 | 2023-08-02 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Spark | 3.1.1 | |||
| Application | Apache | Spark | 3.0.1 | |||
| Application | Apache | Spark | 3.0.0 | |||
| Application | Apache | Spark | 3.0.0 | |||
| Application | Apache | Spark | 3.0.0 | |||
| Application | Apache | Spark | 3.0.0 | |||
| Application | Apache | Spark | 2.4.6 | |||
| Application | Apache | Spark | 2.4.6 | |||
| Application | Apache | Spark | 2.4.6 | |||
| Application | Apache | Spark | 2.4.6 | |||
| Application | Apache | Spark | 2.4.6 | |||
| Application | Apache | Spark | 2.4.6 | |||
| Application | Apache | Spark | 2.4.6 | |||
| Application | Apache | Spark | 2.4.6 | |||
| Application | Apache | Spark | 2.4.6 | |||
| Application | Apache | Spark | 2.4.5 | |||
| Application | Apache | Spark | 2.4.5 | |||
| Application | Apache | Spark | 2.4.5 | |||
| Application | Apache | Spark | 2.4.4 | |||
| Application | Apache | Spark | 2.4.4 |