Skip to content

[Bug]: Security vulnerability in parquet serialization and deserialization #34543

@0xcaffeinated

Description

@0xcaffeinated

What happened?

Recently a maximum severity vulnerability has been found in the apache parquet module of versions 1.15.0 and below. The vulnerability has been listed already in NVD. Attaching the link below:
https://nvd.nist.gov/vuln/detail/CVE-2025-30065#VulnChangeHistorySection

Issue Priority

Priority: 0 (outage / urgent vulnerability)

Issue Components

  • Component: Python SDK
  • Component: Java SDK
  • Component: Go SDK
  • Component: Typescript SDK
  • Component: IO connector
  • Component: Beam YAML
  • Component: Beam examples
  • Component: Beam playground
  • Component: Beam katas
  • Component: Website
  • Component: Infrastructure
  • Component: Spark Runner
  • Component: Flink Runner
  • Component: Samza Runner
  • Component: Twister2 Runner
  • Component: Hazelcast Jet Runner
  • Component: Google Cloud Dataflow Runner

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions