CPANSA-Lucy-2026-61486: Lucy vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2026-08-05T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2026-08-05T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | 9.8 | Severity | Critical |
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Vulnerabilities
CVE-2026-61486
Vulnerability Description** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy.
This issue affects Apache Lucy: all versions.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
Lucy is now maintained outside of the ASF
at https://github.com/lucysearch . This issue has been fixed in 0.8.0 there.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
| Weakness | CWE-121 : Stack-based Buffer Overflow |
|---|
Product status
Known affected
| Product | Score | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Lucy less than 0.8.0 |
|
Fixed
- Lucy greater than or equal 0.8.0
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Lucy-2026-61486 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2026/cpansa-lucy-2026-61486.json - https://nvd.nist.gov/vuln/detail/CVE-2026-61486 external
https://nvd.nist.gov/vuln/detail/CVE-2026-61486 - https://lists.apache.org/thread/z88yv1z19ppsd4td4nqtg7q72fvqh01b external
https://lists.apache.org/thread/z88yv1z19ppsd4td4nqtg7q72fvqh01b - http://www.openwall.com/lists/oss-security/2026/08/05/7 external
http://www.openwall.com/lists/oss-security/2026/08/05/7 - CVE-2026-61486 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2026-61486
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Wed Aug 5 00:00:00 2026 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/