GHSA-rhrv-645h-fjfh
GitHub Security Advisory
Apache Avro Java SDK vulnerable to Improper Input Validation
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system.
This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue.
Affected Packages
Maven
org.apache.avro:avro
Affected versions:
0
(fixed in 1.11.3)
PyPI
avro
Affected versions:
0
(fixed in 1.11.3)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 27, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.