CVE-2026-61486: Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input
UNSUPPORTED WHEN ASSIGNED Stack-based Buffer Overflow vulnerability in Apache Lucy.
This issue affects Apache Lucy: all versions.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
Lucy is now maintained outside of the ASF at https://github.com/lucysearch . This issue has been fixed in 0.8.0 there.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Lucyto a version that resolves this vulnerability.Fixed in 0.8.0 - Compensating control
Restrict access to the Apache Lucy instance to trusted users only (vulnerability affects all versions).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61486?
The severity of CVE-2026-61486 is rated as 55.
How do I fix CVE-2026-61486?
CVE-2026-61486 cannot be fixed as Apache Lucy is an unsupported project and will not receive updates.
What software is affected by CVE-2026-61486?
CVE-2026-61486 affects all versions of Apache Lucy.
What type of vulnerability is CVE-2026-61486?
CVE-2026-61486 is a stack-based buffer overflow vulnerability.
What should users do in response to CVE-2026-61486?
Users are recommended to find an alternative to Apache Lucy or restrict access to the affected instance.