
CVE-2025-60012: Apache Livy: Malicious configuration can lead to unauthorized file access https://www.openwall.com/lists/oss-security/2026/03/12/1 CVE-2025-66249: Apache Livy: Unauthorized directory access (path traversal) https://www.openwall.com/lists/oss-security/2026/03/12/2 Both are "Severity: important"
Post summary
Openwall mailing‑list posts disclose two new Apache Livy CVEs, one exposing unauthorized file access via misconfiguration and another enabling directory traversal; no evidence of active exploitation or patch availability is provided.



