Skip to content

Apache Arrow security advisories

5 advisories · 1 critical or high in 12 months · latest Feb 17

5 advisories

DateAdvisory
Feb 17Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering
CVE-2026-25087High7.0fixed in 23.0.1
Nov 282024Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution. An application is vulnerable if it
CVE-2024-52338Critical9.8fixed in 17.0.0
Nov 92023PyArrow: Arbitrary code execution when loading a malicious data file
CVE-2023-47248Critical9.8fixed in 14.0.1
May 242022Missing Initialization of Resource in Apache Arrow
CVE-2019-12408High7.5fixed in 0.15.1
May 242022Missing Initialization of Resource in Apache Arrow
CVE-2019-12410High7.5fixed in 0.15.1
About Apache Arrow

The columnar in-memory format; pyarrow.

Packages watched: pyarrow (PyPI).

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.