CVE-2025-30065 is a critical remote code execution (RCE) vulnerability affecting Apache Parquet 1.15.0 and earlier, specifically within the parquet-avro module's schema parsing. This flaw allows unauthenticated attackers to execute arbitrary code with high impact on confidentiality, integrity, and availability, as indicated by its CVSS score of 9.8 (CRITICAL). While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community attention with 15 mentions and 6 media articles, suggesting a high potential for future exploitation. Users are strongly advised to upgrade to Apache Parquet version 1.15.1 immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.15.1CPE matchmatch criteria | cpe:2.3:a:apache:parquet_java:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Parquet Avro Module Vulnerable to Arbitrary Code Execution
Apr 1, 2025org.apache.parquet/parquet-avro: Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
Apr 1, 2025