avro
Apache Avro is a data serialization system.
Activity
- Latest release
- 4w ago
- Total releases
- 36
- Cadence
- ~3 months
- Last 12 months
- 3
Reach
- Stars
- 3.3k
Details
- License
- Apache-2.0
- First release
- Jun 10, 2010
| Version | Released | |
|---|---|---|
1.12.2
patch
| ||
1.12.1
patch
| ||
1.11.5
patch
| ||
1.12.0
minor
| ||
1.11.3
patch
1 CVE
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev | ||
1.11.2
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.11.1
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.11.0
minor
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.10.2
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.10.1
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.10.0
minor
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.9.2
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.9.1
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.9.0
minor
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.8.2
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.8.1
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.8.0
minor
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.7.7
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.7.6
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.7.5
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.7.4
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.7.3
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.7.2
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.7.1
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.7.0
minor
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.6.3
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.6.2
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.6.1
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.6.0
minor
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.5.4
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.5.3
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.5.2
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.5.1
patch
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.5.0
minor
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.4.1
minor
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.3.3
initial
2 CVEs
CVE-2025-33042
PYSEC-2026-26
GHSA-rp46-r563-jrc7
Feb 13, 2026
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
+ 20 more Show less
1.5.3
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.5
References Updated May 20, 2026 · Source: OSV.dev
CVE-2023-39410
PYSEC-2023-188
GHSA-rhrv-645h-fjfh
Sep 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue. Affected versions
1.10.0
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.3.3
1.4.1
1.5.0
1.5.1
1.5.2
1.5.3
+ 19 more Show less
1.5.4
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.9.2
Fixed in
1.11.3
References Updated Nov 08, 2023 · Source: OSV.dev |