CVE-2026-32588
Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes. Users are recommended to upgrade to version 4.0.20, 4.1.11, 5.0.7, which fixes this issue.
- Affected products
- Apache Cassandra
- Apache Cassandra
- < 4.0.20, 4.1.11, 5.0.7
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.5% (42th percentile)
- Weakness
- CWE-400
- NVD status
- Analyzed
- Published
- 2026-04-07
CVE-2026-32588 at NVD
No indexed exploits for CVE-2026-32588 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-32588 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.