https://seclists.org/oss-sec/2026/q1/310: CVE-2025-54920: Apache Spark: Spark History Server Code Execution Vulnerability
Published Mar 13, 2026
·Updated
Affected Software
3 affected components
Apache Spark<3.5.7, <4.0.1
maven/org.apache.spark/spark-core_2.13<3.5.7, <4.0.1
maven/org.apache.spark/spark-core_2.12<3.5.7, <4.0.1
Frequently Asked Questions
1
What is the severity of CVE-2025-54920?
The severity of CVE-2025-54920 is classified as low.
2
Which versions of Apache Spark are affected by CVE-2025-54920?
CVE-2025-54920 affects Apache Spark versions before 3.5.7 and 4.0.0 before 4.0.1.
3
How do I fix CVE-2025-54920?
To mitigate CVE-2025-54920, upgrade to Apache Spark version 3.5.7 or 4.0.1 or later.
4
What type of vulnerability is CVE-2025-54920?
CVE-2025-54920 is a code execution vulnerability in the Spark History Server.
5
When was CVE-2025-54920 published?
CVE-2025-54920 was published on March 13, 2026.