CVE-2026-61484Disclosure(apache / lucy)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache lucy systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. Lucy is now maintained outside of the ASF at https://github.com/lucysearch . 0.8.0 is no longer affected by this issue, because the offending feature has been removed there. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lucy

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-05); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
lucy

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-05: 2Mentions · 2026-08-10: 1PoC Mentioned / Linked · 2026-08-10: 1Patch / Workaround · 2026-08-05: 2Technical Details · 2026-08-05: 2Technical Details · 2026-08-10: 108-0508-10
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-052
Disclosure2
2026-08-101
Disclosure1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-61484: Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS https://www.openwall.com/lists/oss-security/2026/08/05/5 Severity: critical Lucy search engine library provides full-text search for dynamic programming languages. It is a "loose C" port of Apache Lucene.

    Post summary

    Apache Lucy’s LucyX::Remote::SearchServer is vulnerable to unauthenticated remote code execution and denial‑of‑service, classified as critical, with details posted on an Openwall mailing list.

    00071671
    4.7K followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    🪦 Apache Lucy: CVE-2026-61484 is a CVSS 9.8 RCE via unauthenticated Storable::thaw deserialization in LucyX::Remote::SearchServer. No patch is coming — the project is retired. If you're still running it, migrate now. #cybersecurity #ciso #vulnerabilities https://secalerts.co/vulnerability/CVE-2026-61484?utm_campaign=x https://t.co/JFxi5bvo7K

    Post summary

    The tweet announces a critical RCE vulnerability (CVE‑2026‑61484) in Apache Lucy, notes no patch will be released as the project is retired, and urges users to migrate.

    0000096
    874 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Apache Lucy Untrusted Deserialization RCE (CVE-2026-61484) Apache Lucy deserializes untrusted data, allowing a crafted serialized payload to trigger gadget execution during object rehydration and achieve remote code execution in the Lucy process context. No fix is planned as the project is retired; only trusted inputs/users should be allowed. 👉Affected: Apache Lucy (all versions)

    Post summary

    The tweet announces a critical CVE‑2026‑61484 in Apache Lucy that permits remote code execution via untrusted deserialization, noting no patch is available and advising to restrict inputs to trusted users.

    00000145
    282 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachelucy---

Explore more