Skip to content
Apache AvroGHSA-r7pg-v2c8-mfg3

Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)

Critical9.8CVE-2024-47561 · Published Oct 3, 2024 · updated Sep 10, 2026

Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgrade to version 1.11.4 or 1.12.0, which fix this issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.avro:avro
Maven
< 1.11.41.11.4
Details and references

More Apache Avro advisories

All Apache Avro
Advisory
Apache Avro Java SDK vulnerable to Improper Input Validation
High7.5Sep 29, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.