CVE-2025-33042 is a Code Injection vulnerability in the Apache Avro Java SDK, affecting all versions through 1.11.4 and version 1.12.0, allowing attackers to inject malicious code when generating records from untrusted Avro schemas. With a CVSS score of 7.3 (HIGH), this vulnerability is easily exploitable over the network without user interaction, potentially leading to low impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog. Users are advised to upgrade to versions 1.12.1 or 1.11.5 to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.11.5CPE matchmatch criteria | cpe:2.3:a:apache:avro:*:*:*:*:*:-:*:* | ||
1.12.0CPE matchmatch criteria | cpe:2.3:a:apache:avro:1.12.0:-:*:*:*:-:*:* | ||
1.12.0CPE matchmatch criteria | cpe:2.3:a:apache:avro:1.12.0:rc0:*:*:*:-:*:* | ||
1.12.0CPE matchmatch criteria | cpe:2.3:a:apache:avro:1.12.0:rc1:*:*:*:-:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Avro Java SDK is Vulnerable to Code Injection
Feb 13, 2026org.apache.avro/avro: Apache Avro Java SDK: Code injection on Java generated code
Feb 13, 2026CVE-2025-33042: Apache Avro Java SDK: Code injection on Java generated code
Feb 12, 2026