Cassandra
Vendor:
First CVE: Apr 3, 2015 · Active for 11 years
16
Total CVEs
More Total CVEs than 92% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
6.3%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Cassandra over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 3, 2015
11 years ago
Most Recent CVE
Apr 7, 2026
108 days ago
CVE Severity & Scoring
Cassandra16 CVEs
38%
44%
19%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (18.8%)
Network12 (75.0%)
Unknown1 (6.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (81.3%)
High2 (12.5%)
Unknown1 (6.3%)
User Interaction
None14 (87.5%)
Unknown1 (6.3%)
Required1 (6.3%)
Privileges Required
Low7 (43.8%)
High1 (6.3%)
None7 (43.8%)
Unknown1 (6.3%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-3427CRITICAL Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and avai | Apr 21, 2016 | 9.8 | 95 | YES | NO |
CVE-2021-44521CRITICAL When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threa | Feb 11, 2022 | 9.1 | 71 | NO | YES |
CVE-2019-2684MEDIUM Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java | Apr 23, 2019 | 5.9 | 40 | NO | NO |
CVE-2018-8016CRITICAL The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbi | Jun 28, 2018 | 9.8 | 31 | NO | NO |
CVE-2016-4970HIGH handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop). | Apr 13, 2017 | 7.5 | 30 | NO | NO |
CVE-2026-27314HIGH Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate identi | Apr 7, 2026 | 8.8 | 29 | NO | NO |
CVE-2025-26467HIGH Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cass | Aug 25, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-23015HIGH Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cass | Feb 4, 2025 | 8.8 | 25 | NO | NO |
CVE-2023-30601HIGH Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra
This issue affects Apache Cassandra: fr | May 30, 2023 | 7.8 | 25 | NO | NO |
CVE-2026-32588MEDIUM Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes.
Users are recommended to upgrade to v | Apr 7, 2026 | 6.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
1 CVE
6.2% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
6.2% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Cassandra
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.0.0 | 1 | 5.3 | 0.3% | 0 | 0 |
| 4.0.0 | 3 | 6.5 | 20.7% | 1 | 0 |
| 3.11.4 | 1 | 7.5 | 11.3% | 0 | 0 |
| 2.1.3 | 1 | 7.5 | 6.7% | 0 | 0 |
| 2.1.2 | 1 | 7.5 | 6.7% | 0 | 0 |
| 2.1.1 | 1 | 7.5 | 6.7% | 0 | 0 |
| 2.1.0 | 1 | 7.5 | 6.7% | 0 | 0 |
| 2.0.9 | 1 | 7.5 | 6.7% | 0 | 0 |
| 2.0.8 | 1 | 7.5 | 6.7% | 0 | 0 |
| 2.0.7 | 1 | 7.5 | 6.7% | 0 | 0 |
| 2.0.6 | 1 | 7.5 | 6.7% | 0 | 0 |
| 2.0.5 | 1 | 7.5 | 6.7% | 0 | 0 |
| 2.0.4 | 1 | 7.5 | 6.7% | 0 | 0 |
| 2.0.3 | 1 | 7.5 | 6.7% | 0 | 0 |
| 2.0.2 | 1 | 7.5 | 6.7% | 0 | 0 |
| 2.0.13 | 1 | 7.5 | 6.7% | 0 | 0 |
| 2.0.12 | 1 | 7.5 | 6.7% | 0 | 0 |
| 2.0.11 | 1 | 7.5 | 6.7% | 0 | 0 |
| 2.0.10 | 1 | 7.5 | 6.7% | 0 | 0 |
| 2.0.1 | 1 | 7.5 | 6.7% | 0 | 0 |