CVE-2026-61483
7.5Apache Software Foundation · Apache Lucy
Apache Lucy is vulnerable to uncontrolled recursion, which may lead to a denial of service condition. As the project is retired, no official patches will be released.
Executive summary
The retired Apache Lucy software contains an uncontrolled recursion vulnerability that allows unauthenticated attackers to cause a denial of service.
Vulnerability
The software is susceptible to uncontrolled recursion (CWE-674), which can be triggered by an unauthenticated attacker to exhaust system resources. This flaw is inherent to the codebase and will not be addressed by the maintainers.
Business impact
Successful exploitation of this vulnerability results in a denial of service, rendering the Apache Lucy instance unresponsive to legitimate users. With a CVSS score of 7.5, the impact is significant for availability, potentially disrupting critical workflows that rely on this software. Given the project is retired, the lack of a vendor-provided patch creates a permanent security risk for any environment still utilizing the library.
Remediation
Immediate Action: Since the project is retired and no fix is available, the only effective remediation is to migrate to an alternative, actively maintained software solution.
Proactive Monitoring: Monitor system logs for unusual spikes in resource consumption or recursive processing errors that may indicate an ongoing denial of service attempt.
Compensating Controls: If immediate migration is impossible, restrict network access to the Apache Lucy instance to known, trusted users and internal systems only to reduce the attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations currently deploying Apache Lucy must prioritize the migration to a supported alternative technology. Because the maintainers have officially retired the project and confirmed that no patches will be issued, continued use of this software exposes the infrastructure to an unfixable denial of service risk. Administrators should perform an impact assessment and finalize a transition plan immediately to eliminate this technical debt.