Skip to content

[GHSA-2c59-37c4-qrx5] Apache Parquet Avro Module Vulnerable to Arbitrary Code Execution#8129

Open
sealbenb wants to merge 1 commit into
sealbenb/advisory-improvement-8129from
sealbenb-GHSA-2c59-37c4-qrx5
Open

[GHSA-2c59-37c4-qrx5] Apache Parquet Avro Module Vulnerable to Arbitrary Code Execution#8129
sealbenb wants to merge 1 commit into
sealbenb/advisory-improvement-8129from
sealbenb-GHSA-2c59-37c4-qrx5

Conversation

@sealbenb

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v4

Comments
Commit apache/parquet-java@a458e1a2 and apache/parquet-java@918609f2cc4e added the reflective getConstructor(String.class) + newInstance(...) path, starting from 1.8.0

Copilot stopped work on behalf of sealbenb due to an error June 25, 2026 16:12
@github-actions github-actions Bot changed the base branch from main to sealbenb/advisory-improvement-8129 June 25, 2026 16:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant