← Back to search

CVE-2026-61485

7.5 HIGH

Published 2026-08-05 · Updated 2026-08-06

AI risk analysis

Summary
The flaw is a memory allocation vulnerability in Apache Lucy that allows for excessive size values, potentially leading to denial of service or other issues. This matters because it can be exploited if an attacker can manipulate input sizes.
Exploitability
Exploitation requires control over input sizes; preconditions include the use of untrusted data in memory allocations.
Blast radius
If exploited, this could impact system availability and performance, affecting users who rely on the service.
Prioritized remediation
Restrict access to trusted users or migrate to an alternative library.
memory-allocdoslegacy

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-789

Vendors

apache

Products

lucy

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.