{"id":"CVE-2026-61484","published":"2026-08-05T08:16:35.487","lastModified":"2026-08-06T18:38:53.463","description":"** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy.\n\nThis issue affects Apache Lucy: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-502"],"vendors":["apache"],"products":["lucy"],"references":[{"url":"https://lists.apache.org/thread/942t3pwgz2nrhnklrtyt5zr7g4wqc9cb","tags":["Mailing List","Vendor Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2026/08/05/5","tags":["Mailing List","Third Party Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is a deserialization vulnerability in Apache Lucy, allowing untrusted data to be deserialized, which can lead to remote code execution or other severe impacts. This matters because it can enable attackers to exploit the software even though it is no longer supported.","exploitability":"Exploitation requires access to deserialize untrusted data, making it moderately difficult but still feasible with the right conditions.","blast_radius":"If exploited, this could result in significant damage, including remote code execution and complete system compromise.","remediation":"Restrict access to instances of Apache Lucy to trusted users or migrate to an alternative solution.","tags":["rce","deserialization","legacy"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:42:46.621Z"}}