CVE-2025-27821: Apache Hadoop
High severity, CVSS 7.3. EPSS: 1% chance of exploitation in the next 30 days.
Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
Affected products
- Apache Hadoop: from 3.2.0, before 3.4.2 (fixed in 3.4.2)
Published 2026-01-26. Last modified 2026-06-17.