CVE-2026-61484: Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS

Published Aug 5, 2026
·
Updated

UNSUPPORTED WHEN ASSIGNED Deserialization of Untrusted Data vulnerability in Apache Lucy.

This issue affects Apache Lucy: all versions.

As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.

Lucy is now maintained outside of the ASF at https://github.com/lucysearch . 0.8.0 is no longer affected by this issue, because the offending feature has been removed there.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Affected Software

4 affected components
Apache Lucy=undefined
Apache LucyX::Remote::SearchServer=undefined
Apache LucyX::mote::SearchServer=undefined
Apache Lucy

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Because Apache Lucy all versions are affected and no fix is planned, restrict access to the Apache Lucy instance to trusted users only (e.g., lock down the network/management endpoints so unauthenticated access to LucyX::Remote::SearchServer / LucyX::mote::SearchServer is not permitted).

  2. Compensating control

    Find an alternative product to Apache Lucy, since the project is retired and the maintainer does not plan to release a fixing version.

Event History

Aug 5, 2026
CVE Published
via MITRE·06:42 AM
Data Sourced
via MITRE·06:42 AM
DescriptionWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-61484?

CVE-2026-61484 has a risk score of 89, indicating it poses a high security threat.

2

What is the nature of the vulnerability in CVE-2026-61484?

CVE-2026-61484 is a deserialization of untrusted data vulnerability that can lead to remote code execution or denial of service.

3

How do I mitigate the risks associated with CVE-2026-61484?

To mitigate CVE-2026-61484, users are advised to restrict access to the affected service or find an alternative to Apache Lucy.

4

Is there a patch available for CVE-2026-61484?

No, CVE-2026-61484 is unsupported, and no patch will be released since Apache Lucy is a retired project.

5

Which versions of Apache Lucy are affected by CVE-2026-61484?

CVE-2026-61484 affects all versions of Apache Lucy.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203