MEDIUM6.5
PYSEC-2026-1157
Apache Superset Allocation of Resources Without Limits or Throttling vulnerability
Quick fix
PYSEC-2026-1157 — apache-superset: upgrade to the fixed version with the command below.
pip install --upgrade 'apache-superset>=3.0.0'Details
An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports, leading to a possible denial of service.
This issue affects Apache Superset: before 3.0.0
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/apache-superset
Introduced in:
0Fixed in: 3.0.0Fix
pip install --upgrade 'apache-superset>=3.0.0'References
- https://nvd.nist.gov/vuln/detail/CVE-2023-42504[ADVISORY]
- https://github.com/apache/superset[PACKAGE]
- https://lists.apache.org/thread/yzq5gk1y9lyw6nxwd3xdkxg1djqw1h6l[WEB]
- http://www.openwall.com/lists/oss-security/2023/11/28/6[WEB]
- https://pypi.org/project/apache-superset[PACKAGE]
- https://github.com/advisories/GHSA-3hp7-4qq4-v5c6[ADVISORY]