{"id":"CVE-2023-39264","aliases":["GHSA-cpvx-2365-466c","BIT-superset-2023-39264","PYSEC-2026-1172"],"title":"Apache Superset may expose internal traces on REST API endpoints","summary":"Apache Superset may expose internal traces on REST API endpoints","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","vendor":"apache-superset","product":"apache-superset","ecosystem":"pip","affected":["apache-superset <= 2.1.0"],"published":"2023-09-06","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-cpvx-2365-466c","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-39264"},{"url":"https://github.com/apache/superset"},{"url":"https://lists.apache.org/thread/y65t1of7hb445n86o1vdzjct7rfwlx75"}],"tags":["osv","pip"],"epss":0.01128,"epssPercentile":0.64437,"ingestedAt":"2026-07-08T18:25:48.422Z","slug":"CVE-2023-39264","body":"## Overview\n\nBy default, stack traces for errors were enabled, which resulted in the exposure of internal traces on REST API endpoints to users. This vulnerability exists in Apache Superset versions up to and including 2.1.0.\n\n## Affected packages\n\n- `apache-superset <= 2.1.0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}