Loading HuntDB...

GHSA-rhrv-645h-fjfh

GitHub Security Advisory

Apache Avro Java SDK vulnerable to Improper Input Validation

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system.

This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue.

Affected Packages

Maven org.apache.avro:avro
Affected versions: 0 (fixed in 1.11.3)
PyPI avro
Affected versions: 0 (fixed in 1.11.3)

Related CVEs

Key Information

GHSA ID
GHSA-rhrv-645h-fjfh
Published
September 29, 2023 6:30 PM
Last Modified
February 13, 2025 7:15 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.apache.avro:avro
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.