Code Injection in Apache Avro - CVE-2025-33042

 

Code Injection in Apache Avro - CVE-2025-33042

Published: March 10, 2026


Vulnerability identifier: #VU123672
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-33042
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability occurs when generating specific records from untrusted Avro schemas. A remote attacker can send a specially crafted request and execute arbitrary code on the target system.


Affected software

Apache Avro
Oracle GoldenGate Big Data and Application Adapters
Communications Unified Assurance
Oracle Business Intelligence Enterprise Edition
Terracotta
StreamSets Data Collector
IBM Cloud Application Performance Management (APM)
Oracle Middleware Common Libraries and Tools
Red Hat Integration Camel Extensions for Quarkus
Oracle Business Process Management Suite
Oracle SOA Suite

How to mitigate CVE-2025-33042

Install updates from vendor's website.

Apache Avro - addressed in versions 1.11.5, 1.12.1
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.19
Terracotta - update to 11.1.0.12
Red Hat Integration Camel Extensions for Quarkus - update to p
StreamSets Data Collector - update to 7.2.0

External References

Related Security Bulletins