Known vulnerabilities in Apache Avro
Vendor:
Apache Foundation
Software:
Apache Avro
Software CPE:
cpe:2.3:a:apache_foundation:avro:*:*:*:*:*:*:*:*
Website:
https://www.apache.org
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU123672 - Improper Control of Generation of Code ('Code Injection') CVE-2025-33042 |
CWE-94 | Medium | 1.11.5, 1.12.1 | 10.03.2026 |
SB2026031037 SB2026031038 SB2026031135 and 8 more |
||
| #VU98024 - Improper input validation CVE-2024-47561 |
CWE-20 | High | 1.11.4, 1.12.0 | 03.10.2024 |
SB2024100351 SB2024100504 SB2024100984 and 36 more |
||
| #VU59280 - Resource exhaustion CVE-2021-43045 |
CWE-400 | Medium | 1.11.0 | 06.01.2022 |
SB2022010628 SB2023101795 SB2024031283 and 1 more |
||
| #VU25334 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2019-17632 |
CWE-79 | Low | 1.9.2 | 13.02.2020 |
SB2019112514 SB2020021330 SB2020010714 and 1 more |
||
| #VU14269 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2017-16042 |
CWE-78 | High | 1.9.2 | 06.08.2018 |
SB2020021330 SB2016090604 |