CVE-2025-54920 | Apache Spark up to 3.5.6/4.0.0 deserialization (EUVD-2025-208669)
A vulnerability was found in Apache Spark up to 3.5.6/4.0.0 and classified as critical. This vulnerability affects unknown code. Such manipulation leads to deserialization.
This vulnerability is listed as CVE-2025-54920. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.