← Back to search

CVE-2026-61483

7.5 HIGH

Published 2026-08-05 · Updated 2026-08-06

AI risk analysis

Summary
Uncontrolled recursion vulnerability in Apache Lucy allows attackers to cause a denial of service by triggering excessive memory consumption.
Exploitability
Exploitation is relatively easy given uncontrolled input can trigger deep recursion leading to resource exhaustion.
Blast radius
If exploited, the impact could be significant as it may lead to system crashes or Denial of Service for affected instances.
Prioritized remediation
Restrict access to Apache Lucy instances to trusted users and consider using alternative search engine solutions.
dosmemory-exhaustionsearch-engine

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-674

Vendors

apache

Products

lucy

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.