Critical Flaw in Apache Parquet Allows Remote Attackers to Execute Arbitrary Code

security flaw that, if properly exploited, might let a remote attacker run arbitrary code on vulnerable instances.

A free and open-source columnar data file format, Apache Parquet supports complex data and offers high-performance compression and encoding strategies for effective data processing and retrieval. In 2013, it was initially introduced.

This particular vulnerability is identified as CVE-2025-30065. It has a 10.0 CVSS score.

According to an alert from the project maintainers, malicious actors can run arbitrary code in Apache Parquet 1.15.0 and earlier versions due to schema parsing in the parquet-avro module.

Endor Labs claims that in order to successfully exploit the vulnerability, a susceptible system must be tricked into reading read more about Critical Flaw in Apache Parquet Allows Remote Attackers to Execute Arbitrary Code.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *