CVE-2026-61486
CVE-2026-61486: 1 tracked advisory record across Apache. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Apache
1 advisory- Advisory severityCritical9.8
Critical [CVE-2026-61486] Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input
CVE-2026-61486Source published Source updated
- * UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. Lucy is now maintained outside of the ASF at. This issue has been fixed in 0.8.0 there. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
- Affected products in this advisory
- Apache Lucy
- Source-reported affected versions
- Apache Lucy before 0.8.0
- Source-reported fixed versions
- 0.8.0
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
- Workarounds
- Users are recommended to find an alternative or restrict access to the instance to trusted users.
Android app · Google Play
Monitor future Apache CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.