---
id: CVE-2023-39264
aliases:
  - GHSA-cpvx-2365-466c
  - BIT-superset-2023-39264
  - PYSEC-2026-1172
title: Apache Superset may expose internal traces on REST API endpoints
summary: Apache Superset may expose internal traces on REST API endpoints
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
vendor: apache-superset
product: apache-superset
ecosystem: pip
affected:
  - apache-superset <= 2.1.0
published: '2023-09-06'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-cpvx-2365-466c'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-39264'
  - url: 'https://github.com/apache/superset'
  - url: 'https://lists.apache.org/thread/y65t1of7hb445n86o1vdzjct7rfwlx75'
tags:
  - osv
  - pip
epss: 0.01128
epssPercentile: 0.64954
ingestedAt: '2026-07-08T18:25:48.422Z'
---

## Overview

By default, stack traces for errors were enabled, which resulted in the exposure of internal traces on REST API endpoints to users. This vulnerability exists in Apache Superset versions up to and including 2.1.0.

## Affected packages

- `apache-superset <= 2.1.0`

## Remediation

Refer to the advisory for the patched release.
