VYPR

Spark History Server

by Apache

CVEs (1)

  • CVE-2026-32773MedSep 2, 2026
    risk 0.40cvss 6.1epss

    There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later. …