Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Yann Gourio

#45946of 56,335
6.1Total CVSS
Vulnerabilities · 1
PT-2026-84664
6.1
2026-09-02
Apache · Spark History Server · CVE-2026-32773
**Name of the Vulnerable Software and Affected Versions** Spark History Server versions prior to 3.5.8 **Description** Insufficient XSS escaping allows a malicious Spark job to generate arbitrary unescaped frontend code. This can lead to a minimal privilege escalation within the browser. Exploitation requires the attacker to have permissions to launch a Spark job and to trick a user with higher privileges into visiting the Spark history web page. **Recommendations** Upgrade to Spark 3.5.8 or later.