CVE-2026-32588

Source
https://cve.org/CVERecord?id=CVE-2026-32588
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-32588.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-32588
Aliases
Downstream
Published
2026-04-07T16:42:52.361Z
Modified
2026-05-18T05:59:55.572409681Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Apache Cassandra: Authenticated DoS via ALTER ROLE Password Hashing
Details

Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes. Users are recommended to upgrade to version 4.0.20, 4.1.11, 5.0.7, which fixes this issue.

Database specific
{
    "cwe_ids": [
        "CWE-400"
    ],
    "cna_assigner": "apache",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32588.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "4.0"
                },
                {
                    "last_affected": "4.0.19"
                },
                {
                    "introduced": "4.1"
                },
                {
                    "last_affected": "4.1.10"
                },
                {
                    "introduced": "5.0"
                },
                {
                    "last_affected": "5.0.6"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/apache/cassandra

Affected ranges

Type
GIT
Repo
https://github.com/apache/cassandra
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "4.0.0"
        },
        {
            "fixed": "4.0.20"
        },
        {
            "introduced": "4.1.0"
        },
        {
            "fixed": "4.1.11"
        },
        {
            "introduced": "5.0.0"
        },
        {
            "fixed": "5.0.7"
        }
    ],
    "source": "CPE_FIELD",
    "cpe": "cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:*"
}

Affected versions

cassandra-4.*
cassandra-4.1.0
cassandra-4.1.1
cassandra-4.1.10
cassandra-4.1.3
cassandra-4.1.4
cassandra-4.1.5
cassandra-4.1.6
cassandra-4.1.7
cassandra-4.1.8
cassandra-4.1.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-32588.json"