AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-32773.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 05, 2026

Disclosure summary

There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later. This CVE is marked as "low" since the path to exploit requires both relatively high permissions (ability to launch a Spark job) and requires tricking a user with higher permissions to log in and visit the Spark history web page. Users are encouraged to upgrade their Spark history servers to Spark 3.5.8 or later.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-9437-39hj-3c93

Open original source · Updated Oct 05, 2026

Apache Spark History Server allows stored cross-site scripting through unescaped application names

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
pippyspark>= 3.0.0, < 3.5.83.5.8
mavenorg.apache.spark:spark-core_2.12>= 3.0.0, < 3.5.83.5.8
mavenorg.apache.spark:spark-core_2.13>= 3.0.0, < 3.5.83.5.8

Original records & references

PUBLISHED 2026-09-02T08:31:29-04:00
MODIFIED 2026-10-05T18:53:38-04:00
INGESTED 2026-10-06T11:45:33-04:00