Skip to main content

Vendor/product archive

apache / avro CVEs

Beta · best-effort

7 CVEs tagged to apache / avro1 Critical, 6 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2025-33042

Published Feb 13, 2026

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects A…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39410

Published Sep 29, 2023

When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This is…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36125

Published Aug 9, 2022

It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previousl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36124

Published Aug 9, 2022

It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Rust applications using Apache Avro R…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-35724

Published Aug 9, 2022

It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications using Apache Avro Rust SDK prior t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43045

Published Jan 6, 2022

A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue affects .NET applicat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1