CVE-2025-55039: Apache Spark has Inadequate Encryption Strength
N/A
CVSS Score
Basic Information
CVE ID
GHSA ID
EPSS Score
0.00481%
CWE
Published
10/15/2025
Updated
10/15/2025
KEV Status
No
Technology
Java
Technical Details
CVSS Vector
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.spark:spark-network-common_2.13 | maven | >= 3.5.0, < 3.5.2 | 3.5.2 |
| org.apache.spark:spark-network-common_2.13 | maven | < 3.4.4 | 3.4.4 |
| org.apache.spark:spark-network-common_2.12 | maven | < 3.4.4 | 3.4.4 |
| org.apache.spark:spark-network-common_2.12 | maven | >= 3.5.0, < 3.5.2 | 3.5.2 |