
CVE-2026-61484: Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS https://www.openwall.com/lists/oss-security/2026/08/05/5 Severity: critical Lucy search engine library provides full-text search for dynamic programming languages. It is a "loose C" port of Apache Lucene.
Post summary
Apache Lucy’s LucyX::Remote::SearchServer is vulnerable to unauthenticated remote code execution and denial‑of‑service, classified as critical, with details posted on an Openwall mailing list.


