CVE-2025-30065
Apache Parquet Avro Module Vulnerable to Arbitrary Code Execution
EPSS 0.38%
Description
Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.
How to fix CVE-2025-30065
To remediate CVE-2025-30065, upgrade the affected package to a fixed version below.
- Maven/org.apache.parquet:parquet-avro—upgrade to 1.15.1 or later
Is CVE-2025-30065 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.15.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A |