Technology · PyPI
pyspark (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 13 vulnerabilities in pyspark (PyPI): 0 in the last 7 days and 1 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2026-32773, was published on 2 September 2026.
- Last 7 days
- 0
- Last 90 days
- 1
- Critical, all time
- 1
- Exploited in the wild
- 1
About pyspark (PyPI)
The Python interface for Apache Spark, providing an API for distributed data processing.
Latest pyspark (PyPI) vulnerabilities
- CVE-2026-32773: Apache Spark History Server XSS in job namesmediumCVSS 6.1EPSS 0.7%
- CVE-2025-55039: Apache Spark Inadequate Encryption Strength in RPC CommunicationmediumCVSS 4EPSS 0.2%
- CVE-2023-32007: PYSEC-2023-72 - ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the…lowCVSS 3.1EPSS 76.0%
- CVE-2023-22946: PYSEC-2023-44 - In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run…lowCVSS 3.1EPSS 1.1%
- CVE-2022-31777: PYSEC-2022-42976 - A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows…lowCVSS 3.1EPSS 1.6%
- CVE-2022-33891: Apache Spark OS command injection in Spark UI via impersonationcriticalexploited in the wildCVSS 8.8EPSS 93.1%
- CVE-2021-38296: PYSEC-2022-186 - Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and…lowCVSS 3.1EPSS 1.8%
- CVE-2020-9480: PYSEC-2020-95 - In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require…lowCVSS 3.1EPSS 29.4%
- PYSEC-2019-44 - Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if…info
- CVE-2019-10099: PYSEC-2019-114 - Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even…lowCVSS 3EPSS 1.3%
- CVE-2018-11760: PYSEC-2019-169 - When using PySpark , it's possible for a different local user to connect to the Spark application and…lowCVSS 3EPSS 0.6%
- CVE-2018-1334: PYSEC-2018-25 - In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for…lowCVSS 3EPSS 0.5%
- CVE-2017-12612: PYSEC-2017-147 - In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by…lowCVSS 3EPSS 0.7%
Most severe pyspark (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2022-33891: Apache Spark OS command injection in Spark UI via impersonationcriticalexploited in the wildCVSS 8.8EPSS 93.1%
- CVE-2026-32773: Apache Spark History Server XSS in job namesmediumCVSS 6.1EPSS 0.7%
- CVE-2025-55039: Apache Spark Inadequate Encryption Strength in RPC CommunicationmediumCVSS 4EPSS 0.2%
- CVE-2023-32007: PYSEC-2023-72 - ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the…lowCVSS 3.1EPSS 76.0%
- CVE-2020-9480: PYSEC-2020-95 - In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require…lowCVSS 3.1EPSS 29.4%
- CVE-2021-38296: PYSEC-2022-186 - Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and…lowCVSS 3.1EPSS 1.8%
- CVE-2022-31777: PYSEC-2022-42976 - A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows…lowCVSS 3.1EPSS 1.6%
- CVE-2023-22946: PYSEC-2023-44 - In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run…lowCVSS 3.1EPSS 1.1%
- CVE-2019-10099: PYSEC-2019-114 - Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even…lowCVSS 3EPSS 1.3%
- CVE-2017-12612: PYSEC-2017-147 - In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by…lowCVSS 3EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 1 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pyspark.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "pyspark (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/pyspark, 28 September 2026.