CVE-2026-61485
7.5 HIGHPublished 2026-08-05 · Updated 2026-08-06
AI risk analysis
- Summary
- The flaw is a memory allocation vulnerability in Apache Lucy that allows for excessive size values, potentially leading to denial of service or other issues. This matters because it can be exploited if an attacker can manipulate input sizes.
- Exploitability
- Exploitation requires control over input sizes; preconditions include the use of untrusted data in memory allocations.
- Blast radius
- If exploited, this could impact system availability and performance, affecting users who rely on the service.
- Prioritized remediation
- Restrict access to trusted users or migrate to an alternative library.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-789
Vendors
apache
Products
lucy
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.