CVE-2025-30065
critical · 10Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.
10
CVSS
43.6%
EPSS (exploit prob.)
99th
EPSS percentile
2025-04-01
Published
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weaknesses
CWE-502
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | parquet_java | < 1.15.1 |
Check a specific version with /api/v1/cve/match.
References
- https://lists.apache.org/thread/okzqb3kn479gqzxm21gg5vqr35om9gw5
- http://www.openwall.com/lists/oss-security/2025/04/01/1
- https://access.redhat.com/security/cve/CVE-2025-30065
- https://github.com/apache/parquet-java/pull/3169
- https://news.ycombinator.com/item?id=43603091
- https://www.bleepingcomputer.com/news/security/max-severity-rce-flaw-discovered-in-widely-used-apache-parquet/
- https://github.com/h3st4k3r/CVE-2025-30065/blob/main/POC-CVE-2025-30065-ParquetExploitGenerator.java
- https://github.com/mouadk/parquet-rce-poc-CVE-2025-30065/blob/main/src/main/java/com/evil/GenerateMaliciousParquetSSRF.java
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-30065