This CVE has been withdrawn by MITRE
MITRE marked CVE-2026-61485 as REJECTED on . There is no longer a valid blast radius to assess. Any historical package or vendor data shown below is preserved for audit reference only.
Reason given by MITRE
this attack requires control over the search index, which is considered fully trusted by Lucy.
CVE-2026-61485 Blast Radius
✕ WITHDRAWN — HISTORICAL DATA** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue affects Apache Lucy: all version…