Known vulnerabilities in Apache Avro

Software: Apache Avro
Software CPE: cpe:2.3:a:apache_foundation:avro:*:*:*:*:*:*:*:*
Total vulnerabilities: 5
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Apache Avro Apache Avro is affected by 5 known vulnerabilities: 2 high, 2 medium, 1 low Critical High Medium Low

Vulnerabilities (5)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU123672 - Improper Control of Generation of Code ('Code Injection')
CVE-2025-33042
CWE-94 Medium
No
No
1.11.5, 1.12.1 10.03.2026 SB2026031037
SB2026031038
SB2026031135
and 8 more
#VU98024 - Improper input validation
CVE-2024-47561
CWE-20 High
No
No
1.11.4, 1.12.0 03.10.2024 SB2024100351
SB2024100504
SB2024100984
and 36 more
#VU59280 - Resource exhaustion
CVE-2021-43045
CWE-400 Medium
No
No
1.11.0 06.01.2022 SB2022010628
SB2023101795
SB2024031283
and 1 more
#VU25334 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-17632
CWE-79 Low
No
No
1.9.2 13.02.2020 SB2019112514
SB2020021330
SB2020010714
and 1 more
#VU14269 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2017-16042
CWE-78 High
No
No
1.9.2 06.08.2018 SB2020021330
SB2016090604