{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/lucy/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:apache:lucy:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-61483"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Lucy"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Apache"],"content_html":"\u003cp\u003eApache Lucy has been identified as containing an uncontrolled recursion vulnerability, tracked as CVE-2026-61483. This flaw allows for potential exploitation due to insufficient bounds checking on recursive calls within the software, which can lead to application crashes or denial-of-service conditions when triggered. The vulnerability affects all versions of the Apache Lucy software. Because the Apache Lucy project is currently retired, the maintainers have confirmed that no security patches will be developed or released to address this issue. Organizations currently utilizing Apache Lucy in their production environments are strongly advised to migrate to alternative software or isolate instances by restricting network access to strictly trusted users.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS v3.1 base score of 7.5, indicating a high risk to availability. Exploitation of the recursion flaw could lead to a persistent denial-of-service state for applications dependent on the library. Since the software is unmaintained, systems remaining on this platform will have no path to remediation, leaving them permanently exposed to any future discovered vulnerabilities.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eConduct an internal audit to identify any legacy instances of Apache Lucy within the environment.\u003c/li\u003e\n\u003cli\u003ePrioritize the migration of all identified Apache Lucy instances to a supported search engine or library alternative.\u003c/li\u003e\n\u003cli\u003eIf migration is not immediately feasible, deploy network segmentation or application-level firewalls to restrict access to the affected instances to only explicitly trusted, internal-only endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T19:26:31Z","date_published":"2026-08-06T19:26:31Z","id":"https://feed.craftedsignal.io/briefs/2026-08-apache-lucy-recursion/","summary":"Apache Lucy, a retired project, contains an uncontrolled recursion vulnerability (CVE-2026-61483) for which no patch will be issued due to the project's end-of-life status.","title":"Uncontrolled Recursion Vulnerability in Apache Lucy","url":"https://feed.craftedsignal.io/briefs/2026-08-apache-lucy-recursion/"}],"language":"en","title":"CraftedSignal Threat Feed - Lucy","version":"https://jsonfeed.org/version/1.1"}