Apache · Spark History Server · CVE-2026-32773
**Name of the Vulnerable Software and Affected Versions**
Spark History Server versions prior to 3.5.8
**Description**
Insufficient XSS escaping allows a malicious Spark job to generate arbitrary unescaped frontend code. This can lead to a minimal privilege escalation within the browser. Exploitation requires the attacker to have permissions to launch a Spark job and to trick a user with higher privileges into visiting the Spark history web page.
**Recommendations**
Upgrade to Spark 3.5.8 or later.