Code Injection Vulnerability in Apache Avro Java SDK
CVE-2025-33042
7.3HIGH
What is CVE-2025-33042?
A code injection vulnerability exists in the Apache Avro Java SDK that allows the generation of code from untrusted Avro schemas. This could potentially lead to the execution of malicious code with the privileges of the user running the application. Users of the affected versions, specifically those prior to 1.12.1 and 1.11.5, are strongly advised to upgrade to the patched versions to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Avro Java SDK 0 <= 1.11.4
Apache Avro Java SDK 1.12.0
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Brant Eckert