Skip to main content

Vendor/product archive

apache / arrow CVEs

Beta · best-effort

5 CVEs tagged to apache / arrow1 Critical, 4 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-25087

Published Feb 17, 2026

Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an I…

CVSS 7.0 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-52338

Published Nov 28, 2024

Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution. An application is vulnera…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-41178

Published Jul 23, 2024

Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and earlier on all platforms using AWS WebIdentityTokens.  On c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12410

Published Nov 8, 2019

While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory Array data uninitialized when r…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12408

Published Nov 8, 2019

It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had a uninitialized memory bug when buildin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1