VulnerabilityAnalyzed
CVE-2025-30065
Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.
CRITICAL 10.0EPSS 43.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 43.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.
- CVSS 4.0
- 10.0 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 43.60% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- apache/parquet java
- Source
- security@apache.org
References
- https://lists.apache.org/thread/okzqb3kn479gqzxm21gg5vqr35om9gw5Mailing List, Release Notes
- http://www.openwall.com/lists/oss-security/2025/04/01/1Mailing List, Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2025-30065Issue Tracking, Third Party Advisory
- https://github.com/apache/parquet-java/pull/3169Issue Tracking, Patch
- https://news.ycombinator.com/item?id=43603091Issue Tracking, Third Party Advisory
- https://www.bleepingcomputer.com/news/security/max-severity-rce-flaw-discovered-in-widely-used-apache-parquet/Exploit, Press/Media Coverage, Third Party Advisory
- https://github.com/h3st4k3r/CVE-2025-30065/blob/main/POC-CVE-2025-30065-ParquetExploitGenerator.javaThird Party Advisory
- https://github.com/mouadk/parquet-rce-poc-CVE-2025-30065/blob/main/src/main/java/com/evil/GenerateMaliciousParquetSSRF.javaThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.