Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes—there is a genuine critical vulnerability, but it is more specific than “Parquet is broken.” CVE-2025-30065 affects Apache Parquet Java’s parquet-avro module when it processes attacker-controlled Avro schema metadata. The practical remediation target is Apache Parquet Java 1.15.2 or later, because a follow-up issue (CVE-2025-46762) means stopping at 1.15.1 can leave some applications exposed.

Whether you are at risk depends on the Java libraries actually deployed, the Avro model used by the read path, and whether an attacker can make your service process a crafted Parquet file.

What is vulnerable—and what is not

Apache Parquet is a columnar file format specification. The vulnerability is in the Java implementation’s Avro integration, not a claim that every Parquet reader or every Parquet file is inherently executable.

  • Apache Parquet Java: the Java implementation and library family.
  • org.apache.parquet:parquet-avro: the module implicated in these CVEs.
  • Apache Avro: supplies schema and object-model behavior used while reading Avro data in Parquet files.
  • Applications: Spark, Hadoop, Flink, ETL services, data-lake jobs and custom ingestion APIs may bring the module into their classpath, sometimes transitively.

The CVE record classifies CVE-2025-30065 as CWE-502, deserialization of untrusted data, and gives it a CVSS 4.0 score of 10.0 Critical. See the CVE record and NVD entry.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the attack works

  1. An attacker creates or modifies a Parquet file.
  2. The file carries attacker-controlled Avro schema information in its metadata.
  3. A vulnerable Java service reads that metadata.
  4. Avro model and class-resolution behavior can instantiate dangerous classes during deserialization.
  5. Code runs with the privileges of the parsing process.

This is not necessarily a conventional exploit against a listening socket. A malicious file can arrive through an upload endpoint, partner feed, shared bucket, data exchange or compromised upstream account. Automatic scanning, previewing, conversion, indexing or querying may be enough to trigger the vulnerable read path. An operator manually opening a file is another possible route.

The impact therefore depends on network reachability, file-processing reachability, user interaction and the parser’s operating-system and cloud permissions. A CVSS score describes the vulnerability under its stated conditions; it does not mean every installation is automatically exploitable.

The two CVEs and the version you should deploy

Issue Affected versions Initial or current fix Practical action
CVE-2025-30065 Apache Parquet Java through 1.15.0 1.15.1 Do not treat 1.15.1 as the final destination where the affected Avro paths are used.
CVE-2025-46762 Versions before 1.15.2 under the advisory’s affected usage conditions 1.15.2 Upgrade to 1.15.2 or a newer supported release.

The first issue was published on April 1, 2025, with 1.15.1 identified as the fix. On May 6, 2025, the follow-up advisory documented a remaining problem in the trusted-package restrictions added in 1.15.1. Its safer floor is 1.15.2.

Why the Avro model matters

Using parquet-avro alone does not establish exploitability. Inspect the code that chooses the Avro data model:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Specific model: directly relevant to the follow-up advisory.
  • Reflect model: directly relevant to the follow-up advisory.
  • Generic model: the CVE-2025-46762 advisory reports this model is not affected by that follow-up issue.

That qualification does not make an old dependency acceptable. The original CVE and the exact application read path still require assessment, and generic-model use should be confirmed rather than assumed from a product name.

Are Spark, Hadoop or Flink installations vulnerable?

There is no defensible blanket answer. A deployment may be exposed only when all of the relevant conditions line up:

  • A vulnerable Apache Parquet Java dependency is actually present in the resolved runtime.
  • The parquet-avro module is present and used.
  • The service processes attacker-controlled Parquet data.
  • The relevant Avro model and code path are enabled.
  • No platform-specific dependency override has removed the vulnerable version.

Check the vendor distribution, dependency graph, packaged JARs and container image instead of inferring risk from “Spark,” “Hadoop” or “Flink” alone.

Check your deployed dependency

Maven

mvn dependency:tree -Dincludes=org.apache.parquet:parquet-avro

Declare a current supported release explicitly where appropriate:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
<dependency>
  <groupId>org.apache.parquet</groupId>
  <artifactId>parquet-avro</artifactId>
  <version>1.15.2</version>
</dependency>

Gradle

./gradlew dependencies --configuration runtimeClasspath
./gradlew dependencyInsight 
  --dependency parquet-avro 
  --configuration runtimeClasspath

Use the newest release approved by your compatibility policy; 1.15.2 is the security floor established by the follow-up advisory, not a reason to pin indefinitely. Verify the resolved version in the deployed artifact. A top-level build file can look fixed while an older transitive, shaded or bundled JAR remains in a container, platform distribution or worker image.

Remediation and temporary containment

Preferred fix: upgrade and redeploy

  1. Find every direct and transitive parquet-avro dependency.
  2. Upgrade Apache Parquet Java to 1.15.2 or later.
  3. Test schema handling, generated specific classes, logical types and downstream readers.
  4. Rebuild images and redeploy every driver, executor, worker, batch job and ingestion service.
  5. Inspect the runtime artifact and confirm no older shaded copy remains.

If an immediate upgrade is impossible

The CVE-2025-46762 advisory identifies this temporary mitigation for affected 1.15.1 deployments:

-Dorg.apache.parquet.avro.SERIALIZABLE_PACKAGES=

Use it only after testing the application’s behavior and confirming that it does not require serializable packages. Apply it consistently to every relevant process, including workers and executors. An empty allowlist is a deployment-specific workaround, not a replacement for upgrading.

Reduce the blast radius

  • Pause acceptance of untrusted Parquet files where feasible.
  • Run parsing and conversion in isolated containers or sandboxes.
  • Use minimal operating-system, cloud and data-lake permissions.
  • Block unnecessary outbound network access from parser workers.
  • Separate inspection or conversion jobs from production credentials.
  • Review logs for unexpected class loading, process creation, outbound connections or unusual ingestion.
  • Ensure SCA and image scanners inspect transitive, shaded and bundled dependencies.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Important edge cases

“Trusted” data lakes are still input boundaries

A shared bucket, partner feed, compromised upstream account or insider can introduce a hostile file. Treat origin-based trust as an assumption to verify, not as parser protection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Encryption does not make unsafe parsing safe

Parquet modular encryption protects file data and metadata under its key-management model, but an authorized parser still processes the decrypted content. It is not a substitute for secure deserialization. See Apache Parquet’s modular encryption documentation.

A scanner finding is not proof of reachability

A dependency scanner may correctly identify an old library even when a dangerous code path is unused. Confirm model selection, input sources and runtime artifacts; do not dismiss the finding solely because ordinary internal files are clean.

Do not confuse this with PyArrow or Arrow R issues

This article concerns Apache Parquet Java’s parquet-avro vulnerabilities. Python, R and other Arrow bindings have separate security histories. For example, NVD documents distinct issues in certain PyArrow versions (CVE-2023-47248) and the Apache Arrow R package (CVE-2024-52338): PyArrow CVE-2023-47248 and Arrow R CVE-2024-52338. Check those projects independently rather than mapping the Java fix to every Parquet reader.

Exposure decision checklist

  1. Is the affected application Java-based?
  2. Is org.apache.parquet:parquet-avro present in the resolved runtime, including shaded JARs?
  3. Can an attacker cause a Parquet file to be uploaded, replaced, submitted or ingested?
  4. Does the read path use Avro specific or reflect models?
  5. Is the resolved version below 1.15.2?
  6. What operating-system, cloud and network permissions does the parser have?

If the answers indicate exposure, upgrade, redeploy and verify the artifact before reopening untrusted ingestion. If malicious files may already have been processed, preserve relevant images and logs and investigate unexpected child processes, class loading and outbound traffic.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Bottom Line

CVE-2025-30065 is a critical Apache Parquet Java parquet-avro deserialization flaw—not a defect in every Parquet implementation. Treat 1.15.2 or later as the remediation target, verify the resolved runtime and Avro model, and isolate parsers that must handle untrusted files.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.