High severity7.5NVD Advisory· Published Aug 9, 2022· Updated Jun 23, 2026
CVE-2022-36124
CVE-2022-36124
Description
It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which addresses this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-avrocrates.io | < 0.14.0 | 0.14.0 |
Affected products
4- Range: <0.14.0
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-wcm8-86x6-8mv3ghsaADVISORY
- lists.apache.org/thread/kj429rzo1xxjgz058qqqg0y7c0p512zonvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-36124ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/avro/PYSEC-2022-43180.yamlghsaWEB
News mentions
0No linked articles in our index yet.