CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-55039: spark before 3.4.4 (exclusive), from 3.5.0 (inclusive), before 3.5.2 (exclusive); +1 more affected products

CVE-2025-55039. CVSS 3.1 base score 6.5 (MEDIUM, Source advisory). EPSS 0.00236 (percentile 0.13323), scored 2026-10-06.

Affected technology

spark · before 3.4.4 (exclusive)
apache

spark · from 3.5.0 (inclusive), before 3.5.2 (exclusive)
apache

Apache Spark · 3.5.0 to before 3.5.2, 0 to before 3.4.4
Apache Software Foundation

Description’s affected range: versions before 3.4.4

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

A man-in-the-middle attacker can modify encrypted RPC traffic undetected by flipping bits in ciphertext, potentially compromising heartbeat messages or application data and affecting the integrity of Spark workflows. Source advisory’s CVSS 3.1 assessment (base score 6.5/10) rates confidentiality and integrity impact as low; availability impact as none.

Published

CWE
CWE-326, CWE-347
CCR priority
26.1 /100 (P4)
CVSS 3.1
6.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N · Source advisory
EPSS
0.00236 · percentile 0.13375 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-55039.html