CPE
Apache Lucy, a retired project, contains an uncontrolled recursion vulnerability (CVE-2026-61483) for which no patch will be issued due to the project's end-of-life status.