CPANSA-Lucy-2026-61486: Lucy vulnerability

Publisher giterlizzi Document category csaf_security_advisory
Initial release date 2026-08-05T00:00:00 Engine CSAF Perl Toolkit 0.26
Current release date 2026-08-05T00:00:00 Build Date
Current version 1 Status final
CVSS v3.1 Base Score 9.8 Severity Critical
Original language Language en
Also referred to

Vulnerability Description

Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Vulnerabilities

CVE-2026-61486

Vulnerability Description

** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy.



This issue affects Apache Lucy: all versions.



As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.



Lucy is now maintained outside of the ASF
at https://github.com/lucysearch . This issue has been fixed in 0.8.0 there.



NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Weakness CWE-121 : Stack-based Buffer Overflow

Product status

Known affected
Product Score
Lucy greater than 0
CVSS Version CVSS Vector CVSS Base Score CVSS Base Severity
3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 9.8 Critical

giterlizzi

Namespace: https://github.com/giterlizzi/

gdt@cpan.org

References

Revision history

Version Date of the revision Summary of the revision
1 Wed Aug 5 00:00:00 2026 First release

Sharing rules

TLP:WHITE
For the TLP version see: https://www.first.org/tlp/