{"schema_version":1,"title":"pyspark (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 13 vulnerabilities in pyspark (PyPI): 0 in the last 7 days and 1 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2026-32773, was published on 2 September 2026.","url":"https://junglewise.ai/threats/technologies/pyspark","json_url":"https://junglewise.ai/threats/technologies/pyspark.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/pyspark","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":13,"critical":1,"exploited":1,"last_7_days":0,"last_30_days":1,"last_90_days":1,"last_365_days":2},"latest":[{"cve":"CVE-2026-32773","cvss":6.1,"epss":0.0068,"slug":"cve-2026-32773-apache-spark-history-server-xss-in-job-names","title":"Apache Spark History Server XSS in job names","severity":"medium","exploited":false,"published_at":"2026-09-02T11:17:20.173+00:00","url":"https://junglewise.ai/threats/cve-2026-32773-apache-spark-history-server-xss-in-job-names"},{"cve":"CVE-2025-55039","cvss":4,"epss":0.0024,"slug":"cve-2025-55039-apache-spark-inadequate-encryption-strength-in-rpc-communication","title":"Apache Spark Inadequate Encryption Strength in RPC Communication","severity":"medium","exploited":false,"published_at":"2025-10-15T09:30:17+00:00","url":"https://junglewise.ai/threats/cve-2025-55039-apache-spark-inadequate-encryption-strength-in-rpc-communication"},{"cve":"CVE-2023-32007","cvss":3.1,"epss":0.7596,"slug":"cve-2023-32007-apache-spark-ui-vulnerable-to-command-injection","title":"PYSEC-2023-72 - ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. Wi","severity":"low","exploited":false,"published_at":"2023-05-02T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-32007-apache-spark-ui-vulnerable-to-command-injection"},{"cve":"CVE-2023-22946","cvss":3.1,"epss":0.0111,"slug":"cve-2023-22946-apache-spark-privilege-escalation-via-classpath-injection","title":"PYSEC-2023-44 - In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The appl","severity":"low","exploited":false,"published_at":"2023-04-17T08:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-22946-apache-spark-privilege-escalation-via-classpath-injection"},{"cve":"CVE-2022-31777","cvss":3.1,"epss":0.0158,"slug":"cve-2022-31777-apache-spark-vulnerable-to-log-injection","title":"PYSEC-2022-42976 - A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary","severity":"low","exploited":false,"published_at":"2022-11-01T16:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-31777-apache-spark-vulnerable-to-log-injection"},{"cve":"CVE-2022-33891","cvss":8.8,"epss":0.9308,"slug":"cve-2022-33891-apache-spark-os-command-injection-in-spark-ui-via-impersonation","title":"Apache Spark OS command injection in Spark UI via impersonation","severity":"critical","exploited":true,"published_at":"2022-07-19T00:00:29+00:00","url":"https://junglewise.ai/threats/cve-2022-33891-apache-spark-os-command-injection-in-spark-ui-via-impersonation"},{"cve":"CVE-2021-38296","cvss":3.1,"epss":0.0185,"slug":"cve-2021-38296-authentication-bypass-by-capture-replay-in-apache-spark","title":"PYSEC-2022-186 - Apache Spark supports end-to-end encryption of RPC connections via \"spark.authenticate\" and \"spark.network.crypto.enabled\". In versions 3.1.","severity":"low","exploited":false,"published_at":"2022-03-10T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-38296-authentication-bypass-by-capture-replay-in-apache-spark"},{"cve":"CVE-2020-9480","cvss":3.1,"epss":0.2937,"slug":"cve-2020-9480-improper-authentication-in-apache-spark","title":"PYSEC-2020-95 - In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) v","severity":"low","exploited":false,"published_at":"2020-06-23T22:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-9480-improper-authentication-in-apache-spark"},{"slug":"pysec-2019-44-prior-to-spark-2-3-3-in-certain-situations-spark-would-4f667101","title":"PYSEC-2019-44 - Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true.","severity":"info","exploited":false,"published_at":"2019-08-07T17:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2019-44-prior-to-spark-2-3-3-in-certain-situations-spark-would-4f667101"},{"cve":"CVE-2019-10099","cvss":3,"epss":0.013,"slug":"cve-2019-10099-sensitive-data-written-to-disk-unencrypted-in-spark","title":"PYSEC-2019-114 - Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true.","severity":"low","exploited":false,"published_at":"2019-08-07T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2019-10099-sensitive-data-written-to-disk-unencrypted-in-spark"},{"cve":"CVE-2018-11760","cvss":3,"epss":0.0061,"slug":"cve-2018-11760-pyspark-user-impersonation-vulnerability","title":"PYSEC-2019-169 - When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark","severity":"low","exploited":false,"published_at":"2019-02-04T17:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-11760-pyspark-user-impersonation-vulnerability"},{"cve":"CVE-2018-1334","cvss":3,"epss":0.0051,"slug":"cve-2018-1334-exposure-of-sensitive-information-to-an-unauthorized-actor-in","title":"PYSEC-2018-25 - In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect","severity":"low","exploited":false,"published_at":"2018-07-12T13:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-1334-exposure-of-sensitive-information-to-an-unauthorized-actor-in"},{"cve":"CVE-2017-12612","cvss":3,"epss":0.0073,"slug":"cve-2017-12612-apache-spark-deserialization-of-untrusted-data-vulnerability","title":"PYSEC-2017-147 - In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications","severity":"low","exploited":false,"published_at":"2017-09-13T16:29:00+00:00","url":"https://junglewise.ai/threats/cve-2017-12612-apache-spark-deserialization-of-untrusted-data-vulnerability"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"pyspark (PyPI)","slug":"pyspark","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://spark.apache.org/docs/latest/api/python/index.html","repo_url":"https://github.com/apache/spark/tree/master/python","description":"The Python interface for Apache Spark, providing an API for distributed data processing.","url":"https://junglewise.ai/threats/technologies/pyspark"},"most_severe":[{"cve":"CVE-2022-33891","cvss":8.8,"epss":0.9308,"slug":"cve-2022-33891-apache-spark-os-command-injection-in-spark-ui-via-impersonation","title":"Apache Spark OS command injection in Spark UI via impersonation","severity":"critical","exploited":true,"published_at":"2022-07-19T00:00:29+00:00","url":"https://junglewise.ai/threats/cve-2022-33891-apache-spark-os-command-injection-in-spark-ui-via-impersonation"},{"cve":"CVE-2026-32773","cvss":6.1,"epss":0.0068,"slug":"cve-2026-32773-apache-spark-history-server-xss-in-job-names","title":"Apache Spark History Server XSS in job names","severity":"medium","exploited":false,"published_at":"2026-09-02T11:17:20.173+00:00","url":"https://junglewise.ai/threats/cve-2026-32773-apache-spark-history-server-xss-in-job-names"},{"cve":"CVE-2025-55039","cvss":4,"epss":0.0024,"slug":"cve-2025-55039-apache-spark-inadequate-encryption-strength-in-rpc-communication","title":"Apache Spark Inadequate Encryption Strength in RPC Communication","severity":"medium","exploited":false,"published_at":"2025-10-15T09:30:17+00:00","url":"https://junglewise.ai/threats/cve-2025-55039-apache-spark-inadequate-encryption-strength-in-rpc-communication"},{"cve":"CVE-2023-32007","cvss":3.1,"epss":0.7596,"slug":"cve-2023-32007-apache-spark-ui-vulnerable-to-command-injection","title":"PYSEC-2023-72 - ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. Wi","severity":"low","exploited":false,"published_at":"2023-05-02T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-32007-apache-spark-ui-vulnerable-to-command-injection"},{"cve":"CVE-2020-9480","cvss":3.1,"epss":0.2937,"slug":"cve-2020-9480-improper-authentication-in-apache-spark","title":"PYSEC-2020-95 - In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) v","severity":"low","exploited":false,"published_at":"2020-06-23T22:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-9480-improper-authentication-in-apache-spark"},{"cve":"CVE-2021-38296","cvss":3.1,"epss":0.0185,"slug":"cve-2021-38296-authentication-bypass-by-capture-replay-in-apache-spark","title":"PYSEC-2022-186 - Apache Spark supports end-to-end encryption of RPC connections via \"spark.authenticate\" and \"spark.network.crypto.enabled\". In versions 3.1.","severity":"low","exploited":false,"published_at":"2022-03-10T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-38296-authentication-bypass-by-capture-replay-in-apache-spark"},{"cve":"CVE-2022-31777","cvss":3.1,"epss":0.0158,"slug":"cve-2022-31777-apache-spark-vulnerable-to-log-injection","title":"PYSEC-2022-42976 - A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary","severity":"low","exploited":false,"published_at":"2022-11-01T16:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-31777-apache-spark-vulnerable-to-log-injection"},{"cve":"CVE-2023-22946","cvss":3.1,"epss":0.0111,"slug":"cve-2023-22946-apache-spark-privilege-escalation-via-classpath-injection","title":"PYSEC-2023-44 - In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The appl","severity":"low","exploited":false,"published_at":"2023-04-17T08:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-22946-apache-spark-privilege-escalation-via-classpath-injection"},{"cve":"CVE-2019-10099","cvss":3,"epss":0.013,"slug":"cve-2019-10099-sensitive-data-written-to-disk-unencrypted-in-spark","title":"PYSEC-2019-114 - Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true.","severity":"low","exploited":false,"published_at":"2019-08-07T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2019-10099-sensitive-data-written-to-disk-unencrypted-in-spark"},{"cve":"CVE-2017-12612","cvss":3,"epss":0.0073,"slug":"cve-2017-12612-apache-spark-deserialization-of-untrusted-data-vulnerability","title":"PYSEC-2017-147 - In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications","severity":"low","exploited":false,"published_at":"2017-09-13T16:29:00+00:00","url":"https://junglewise.ai/threats/cve-2017-12612-apache-spark-deserialization-of-untrusted-data-vulnerability"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}