CVE-2025-27821: Apache Hadoop

High severity, CVSS 7.3. EPSS: 1% chance of exploitation in the next 30 days.

Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

Affected products

  • Apache Hadoop: from 3.2.0, before 3.4.2 (fixed in 3.4.2)

Published 2026-01-26. Last modified 2026-06-17.