Get real-time updates on Telegram
CVE-2025-55039: spark before 3.4.4 (exclusive), from 3.5.0 (inclusive), before 3.5.2 (exclusive); +1 more affected products
CVE-2025-55039. CVSS 3.1 base score 6.5 (MEDIUM, Source advisory). EPSS 0.00236 (percentile 0.13323), scored 2026-10-06.
Affected technology
spark · before 3.4.4 (exclusive)
apache
spark · from 3.5.0 (inclusive), before 3.5.2 (exclusive)
apache
Apache Spark · 3.5.0 to before 3.5.2, 0 to before 3.4.4
Apache Software Foundation
Description’s affected range: versions before 3.4.4
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
A man-in-the-middle attacker can modify encrypted RPC traffic undetected by flipping bits in ciphertext, potentially compromising heartbeat messages or application data and affecting the integrity of Spark workflows. Source advisory’s CVSS 3.1 assessment (base score 6.5/10) rates confidentiality and integrity impact as low; availability impact as none.
- CWE
- CWE-326, CWE-347
- CCR priority
- 26.1 /100 (P4)
- CVSS 3.1
- 6.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N · Source advisory
- EPSS
- 0.00236 · percentile 0.13375 · 2026-10-08
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-08 17:36:22.845483+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 17:32:11.049884+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-55039.html