{"api_version":"v1","generated_at":"2026-10-06T02:35:00+00:00","product":{"cve_count":14,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-apache-software-foundation-apache-spark-d97169fe2747","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Apache Spark","next_cursor":null,"observations":[{"affected":"3.0.0 < 3.5.8","affected_versions_present":true,"cve_id":"CVE-2026-32773","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32773","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-02T12:43:56.359Z","patch_url":"","primary_source":"","published":"2026-09-02T10:51:17.197Z"},{"affected":"< 3.5.7; 4.0.0 < 4.0.1","affected_versions_present":true,"cve_id":"CVE-2025-54920","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54920","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-17T12:45:29.903Z","patch_url":"https://lists.apache.org/thread/4y9n0nfj7m68o2hpmoxgc0y7dm1lo02s","primary_source":"","published":"2026-03-14T09:01:50.486Z"},{"affected":"3.5.0 < 3.5.2; < 3.4.4","affected_versions_present":true,"cve_id":"CVE-2025-55039","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-55039","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-04T21:13:00.940Z","patch_url":"","primary_source":"","published":"2025-10-15T07:19:25.493Z"},{"affected":"3.1.1 < 3.2.2","affected_versions_present":true,"cve_id":"CVE-2023-32007","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-32007","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-13T16:50:19.521Z","patch_url":"","primary_source":"","published":"2023-05-02T08:37:22.118Z"},{"affected":"< 3.4.0","affected_versions_present":true,"cve_id":"CVE-2023-22946","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22946","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-10-21T15:06:58.145Z","patch_url":"","primary_source":"","published":"2023-04-17T07:30:19.865Z"},{"affected":"3.3.0; 3.2.1 and earlier \u2264 3.2.1","affected_versions_present":true,"cve_id":"CVE-2022-31777","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-31777","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-05-06T03:36:31.908Z","patch_url":"","primary_source":"","published":"2022-11-01T00:00:00.000Z"},{"affected":"up to and including version 3.1.2 \u2264 3.1.2","affected_versions_present":true,"cve_id":"CVE-2021-38296","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-38296","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T01:37:16.315Z","patch_url":"https://www.oracle.com/security-alerts/cpujul2022.html","primary_source":"","published":"2022-03-10T08:20:12.000Z"},{"affected":"Apache Spark 2.4.5 and earlier","affected_versions_present":true,"cve_id":"CVE-2020-9480","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-9480","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T10:26:16.324Z","patch_url":"https://www.oracle.com/security-alerts/cpuApr2021.html","primary_source":"","published":"2020-06-23T21:50:51.000Z"},{"affected":"Apache Spark 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1","affected_versions_present":true,"cve_id":"CVE-2018-11760","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-11760","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-16T19:19:24.731Z","patch_url":"","primary_source":"","published":"2019-02-04T17:00:00.000Z"},{"affected":"All versions","affected_versions_present":true,"cve_id":"CVE-2018-17190","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-17190","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-05T10:39:59.689Z","patch_url":"","primary_source":"","published":"2018-11-19T14:00:00.000Z"},{"affected":"1.3.0 < 3.*","affected_versions_present":true,"cve_id":"CVE-2018-11804","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-11804","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-05T08:17:09.224Z","patch_url":"https://spark.apache.org/security.html#CVE-2018-11804","primary_source":"","published":"2018-10-24T00:00:00.000Z"},{"affected":"1.3.0 < 2.4.0","affected_versions_present":true,"cve_id":"CVE-2018-11770","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-11770","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-05T08:17:09.223Z","patch_url":"https://spark.apache.org/security.html#CVE-2018-11770","primary_source":"","published":"2018-08-13T00:00:00.000Z"},{"affected":"1.0.0 to 2.1.2; 2.2.0 to 2.2.1; 2.3.0","affected_versions_present":true,"cve_id":"CVE-2018-8024","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-8024","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-17T02:10:38.073Z","patch_url":"https://spark.apache.org/security.html#CVE-2018-8024","primary_source":"","published":"2018-07-12T13:00:00.000Z"},{"affected":"1.0.0 to 2.1.2; 2.2.0 to 2.2.1; 2.3.0","affected_versions_present":true,"cve_id":"CVE-2018-1334","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-1334","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-17T03:22:59.383Z","patch_url":"https://spark.apache.org/security.html#CVE-2018-1334","primary_source":"","published":"2018-07-12T13:00:00.000Z"}],"source_generated_at":"2026-10-05T06:20:29.126Z","vendor":"Apache Software Foundation"}}
