This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0.
Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rp46-r563-jrc7 | Apache Avro Java SDK is Vulnerable to Code Injection |
Fri, 20 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:avro:*:*:*:*:*:-:*:* cpe:2.3:a:apache:avro:1.12.0:-:*:*:*:-:*:* cpe:2.3:a:apache:avro:1.12.0:rc0:*:*:*:-:*:* cpe:2.3:a:apache:avro:1.12.0:rc1:*:*:*:-:*:* |
Sat, 14 Feb 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 13 Feb 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache avro |
|
| Vendors & Products |
Apache
Apache avro |
Fri, 13 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 13 Feb 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 13 Feb 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue. | |
| Title | Apache Avro Java SDK: Code injection on Java generated code | |
| Weaknesses | CWE-94 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-02-13T18:05:35.038Z
Reserved: 2025-04-15T15:57:08.995Z
Link: CVE-2025-33042
Updated: 2026-02-13T12:11:10.364Z
Status : Analyzed
Published: 2026-02-13T12:16:07.570
Modified: 2026-02-20T15:07:04.680
Link: CVE-2025-33042
OpenCVE Enrichment
Updated: 2026-02-13T21:28:42Z
Github GHSA