{"id":"CVE-2026-61485","published":"2026-08-05T08:16:35.610","lastModified":"2026-08-06T18:38:47.943","description":"** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy.\n\nThis issue affects Apache Lucy: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-789"],"vendors":["apache"],"products":["lucy"],"references":[{"url":"https://lists.apache.org/thread/4q9rfscp3tkjr3kt7lsg97szhmydl23s","tags":["Mailing List","Vendor Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2026/08/05/6","tags":["Mailing List","Third Party Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is a memory allocation vulnerability in Apache Lucy that allows for excessive size values, potentially leading to denial of service or other issues. This matters because it can be exploited if an attacker can manipulate input sizes.","exploitability":"Exploitation requires control over input sizes; preconditions include the use of untrusted data in memory allocations.","blast_radius":"If exploited, this could impact system availability and performance, affecting users who rely on the service.","remediation":"Restrict access to trusted users or migrate to an alternative library.","tags":["memory-alloc","dos","legacy"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:58:30.729Z"}}