VYPR

Parquet Java

by Apache

Source repositories

CVEs (3)

  • CVE-2025-30065CriApr 1, 2025
    risk 0.60cvss 9.8epss 0.41

    Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.

  • CVE-2025-46762HigMay 6, 2025
    risk 0.53cvss 8.1epss 0.01

    Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code. While 1.15.1 introduced a fix to restrict untrusted packages, the default setting of trusted packages still allows malicious classes from these…

  • CVE-2021-41561HigDec 20, 2021
    risk 0.49cvss 7.5epss 0.03

    Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apache Parquet-MR version 1.9.0 and later versions.