CVE-2025-30065: Apache Parquet Java

Critical severity, CVSS 9.8. EPSS: 43.6% chance of exploitation in the next 30 days.

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.

Affected products

  • Apache Parquet Java: before 1.15.1 (fixed in 1.15.1)

Published 2025-04-01. Last modified 2026-06-17.