Skip to content
Apache ParquetGHSA-2c59-37c4-qrx5

Apache Parquet Avro Module Vulnerable to Arbitrary Code Execution

CriticalCVE-2025-30065 · Published Apr 1, 2025 · updated Sep 10, 2026

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.parquet:parquet-avro
Maven
< 1.15.11.15.1
Details and references

More Apache Parquet advisories

All Apache Parquet
Advisory
Apache Parquet: code execution
HighMay 6, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.