CVE-2025-33042
EUVD-2025-20691013.02.2026, 12:16
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas.
This issue affects Apache Avro Java SDK: all versions through 1.11.4 and versionĀ 1.12.0.
Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue.Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | avro | 𝑥 < 1.11.5 |
| apache | avro | 1.12.0 |
| apache | avro | 1.12.0:rc0 |
| apache | avro | 1.12.0:rc1 |
𝑥
= Vulnerable software versions