CVE-2023-42504: Apache Superset

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports, leading to a possible denial of service. This issue affects Apache Superset: before 3.0.0

Affected products

  • Apache Superset: before 3.0.0 (fixed in 3.0.0)

Published 2023-11-28. Last modified 2026-06-17.