Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-61486: Apache Lucy: Unpatched Buffer Overflow Risk

CVE-2026-61486 CVE-2026-61486
Summary

All versions of Apache Lucy are affected. Since this project is no longer maintained, you won't receive a fix. Consider switching to a supported alternative or limiting access to trusted users to minimize the risk.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
apache software foundation apache lucy <= *
Original title
** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a ver...
Original description
** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy.

This issue affects Apache Lucy: all versions.

As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Vulnerability type
CWE-121 Stack-based Buffer Overflow
Published: 5 Aug 2026 · Updated: 5 Aug 2026 · First seen: 5 Aug 2026