PYSEC-2026-3966

    Dashboard / Vulnerabilities / PYSEC-2026-3966

    PYSEC-2026-3966

    Published: 2 Sept 2026Last Modified: 10 Sept 2026

    Summary:

    Details: There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later. This CVE is marked as "low" since the path to exploit requires both relatively high permissions (ability to launch a Spark job) and requires tricking a user with higher permissions to log in and visit the Spark history web page. Users are encouraged to upgrade their Spark history servers to Spark 3.5.8 or later.

    Affected packages

    Package

    Name: pyspark

    Purl: pkg:pypi/pyspark

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 3.0.0
    Fixed -3.5.8

    Affected versions

    3.0.0
    3.0.1
    3.0.2
    3.0.3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    PYSEC-2026-3966 | CVE-DB