Apache Arrow security advisories
5 advisories · 1 critical or high in 12 months · latest Feb 17
5 advisories
| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 17 | Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering CVE-2026-25087High7.0fixed in 23.0.1 | High7.0 | 23.0.1 |
| Nov 282024 | Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution. An application is vulnerable if it CVE-2024-52338Critical9.8fixed in 17.0.0 | Critical9.8 | 17.0.0 |
| Nov 92023 | PyArrow: Arbitrary code execution when loading a malicious data file CVE-2023-47248Critical9.8fixed in 14.0.1 | Critical9.8 | 14.0.1 |
| May 242022 | Missing Initialization of Resource in Apache Arrow CVE-2019-12408High7.5fixed in 0.15.1 | High7.5 | 0.15.1 |
| May 242022 | Missing Initialization of Resource in Apache Arrow CVE-2019-12410High7.5fixed in 0.15.1 | High7.5 | 0.15.1 |