Skip to content
VulniPulse
Highest advisory severityCritical 1 vendor · 1 advisory

CVE-2026-61486

CVE-2026-61486: 1 tracked advisory record across Apache. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Apache

1 advisory
  • Advisory severityCritical9.8

    Critical [CVE-2026-61486] Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input

    CVE-2026-61486Source published Source updated

    - * UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. Lucy is now maintained outside of the ASF at. This issue has been fixed in 0.8.0 there. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Affected products in this advisory
    • Apache Lucy
    Source-reported affected versions
    • Apache Lucy before 0.8.0
    Source-reported fixed versions
    • 0.8.0
    Mitigation guidance
    No mitigation guidance extracted; consult the source.
    Workarounds
    • Users are recommended to find an alternative or restrict access to the instance to trusted users.

Android app · Google Play

Monitor future Apache CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery