PT-2026-98426 · Cleanstart · Apache Superset

Published

2026-09-15

·

Updated

2026-09-15

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Multiple security vulnerabilities affect the apache-superset package. undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response's status and headers. See references for individual vulnerability details.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CLEANSTART-2026-EC11110

Affected Products

Apache Superset