Critical RCE Vulnerability in Apache Parquet (CVE-2025-30065) – Advisory and Analysis
Blog post from Endor Labs
A critical security vulnerability identified as CVE-2025-30065 has been found in Apache Parquet's Java library, specifically within the parquet-avro module, and has been rated as "Critical" with a CVSS score of 10.0. This flaw, classified as Deserialization of Untrusted Data (CWE-502), poses serious risks to systems that import Parquet files from untrusted sources, potentially allowing attackers to gain remote code execution, steal or tamper with data, install malware, or disrupt services. All systems using Apache Parquet Java library versions 1.15.0 or earlier are considered vulnerable, with the issue reportedly introduced in version 1.8.0. Although there have been no known reports of active exploitation as of early April 2025, the public awareness of the vulnerability suggests that attackers may develop exploits. Immediate action is advised, including upgrading to version 1.15.1 or later, avoiding or validating untrusted Parquet files, and enhancing monitoring and logging to detect suspicious activities. Organizations are urged to stay informed about further advisories and updates from Apache or other cybersecurity authorities to mitigate the risk effectively.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.