<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cpe:2.3:a:apache:lucy:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aapachelucy/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 06 Aug 2026 19:26:31 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aapachelucy/feed.xml" rel="self" type="application/rss+xml"/><item><title>Uncontrolled Recursion Vulnerability in Apache Lucy</title><link>https://feed.craftedsignal.io/briefs/2026-08-apache-lucy-recursion/</link><pubDate>Thu, 06 Aug 2026 19:26:31 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-apache-lucy-recursion/</guid><description>Apache Lucy, a retired project, contains an uncontrolled recursion vulnerability (CVE-2026-61483) for which no patch will be issued due to the project's end-of-life status.</description><content:encoded><![CDATA[<p>Apache Lucy has been identified as containing an uncontrolled recursion vulnerability, tracked as CVE-2026-61483. This flaw allows for potential exploitation due to insufficient bounds checking on recursive calls within the software, which can lead to application crashes or denial-of-service conditions when triggered. The vulnerability affects all versions of the Apache Lucy software. Because the Apache Lucy project is currently retired, the maintainers have confirmed that no security patches will be developed or released to address this issue. Organizations currently utilizing Apache Lucy in their production environments are strongly advised to migrate to alternative software or isolate instances by restricting network access to strictly trusted users.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability carries a CVSS v3.1 base score of 7.5, indicating a high risk to availability. Exploitation of the recursion flaw could lead to a persistent denial-of-service state for applications dependent on the library. Since the software is unmaintained, systems remaining on this platform will have no path to remediation, leaving them permanently exposed to any future discovered vulnerabilities.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Conduct an internal audit to identify any legacy instances of Apache Lucy within the environment.</li>
<li>Prioritize the migration of all identified Apache Lucy instances to a supported search engine or library alternative.</li>
<li>If migration is not immediately feasible, deploy network segmentation or application-level firewalls to restrict access to the affected instances to only explicitly trusted, internal-only endpoints.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category></item></channel></rss>