← Back to search

CVE-2026-61486

9.8 CRITICAL

Published 2026-08-05 · Updated 2026-08-06

AI risk analysis

Summary
A stack-based buffer overflow vulnerability exists in Apache Lucy, allowing attackers to potentially execute arbitrary code through crafted input.
Exploitability
Exploitation is likely if an attacker can send malicious input, but since the project is retired, no active exploits are available.
Blast radius
If exploited, this could result in complete compromise of affected systems and data loss.
Prioritized remediation
Discontinue use of Apache Lucy and migrate to a supported alternative.
buffer-overflowrceretired-project

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-121

Vendors

apache

Products

lucy

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.