CVE-2026-32588

EUVD-2026-19769
Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes.
Users are recommended to upgrade to version 4.0.20, 4.1.11, 5.0.7, which fixes this issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 26%
Affected Products (NVD)
VendorProductVersion
apachecassandra
4.0.0 ≤
𝑥
< 4.0.20
apachecassandra
4.1.0 ≤
𝑥
< 4.1.11
apachecassandra
5.0.0 ≤
𝑥
< 5.0.7
𝑥
= Vulnerable software versions