peter bassill · operator
$ cve CVE-2025-30065 JSON

CVE-2025-30065

9.8
CRITICAL · CVSS 3.1 · EPSS 43.6% (pctl 99)

Patch early

EPSS 43.6% — above the 10% action threshold.

Description

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS43.6% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2025-04-01
Last modified2026-06-17

Affected (1)

VendorProduct
apacheparquet java

References

→ the Explorer  ·  watch your stack  ·  NVD