GHSA-phg2-9c5g-m4q7 · Severity: critical · Ecosystem: maven — Remote Code Execution in spark-core
In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hosts. The master itself does not, by design, execute user code. A specially-crafted request to the master can, however, cause the master to execute code too. Note that this does not affect standalone clusters with authentication enabled. While the master host typically has less outbound access to other resources than a worker, the execution of code on the master is nevertheless unexpected.
Conclusion & alert: CVE-2018-17190 is rated High Risk (77.3/100): CVSS Critical severity, with high exploitation likelihood (EPSS 8.72%, 94th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +7.57% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 1.15% | 8.72% | +7.57% |
| 2 | 2026-06-05 | 1.21% | 1.15% | -0.06% |
| 3 | 2025-11-21 | — | 1.21% | — |
Full EPSS history (23 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.0 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
GHSA-phg2-9c5g-m4q7 · Severity: critical · Ecosystem: maven — Remote Code Execution in spark-core
| vendor | priority | summary | link |
|---|---|---|---|
gentoo
|
normal | CVE-2018-17190: 1 GLSA(s) (201903-21), 1 atom(s) (www-servers/apache); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2018-17190 |