pyarrow
PyPI5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting pyarrowpage 1 of 1
- CVE-2019-12408HIGHCVSS 7.5EG 7.5✓ Fixed in 0.15.12019-11-08
vulnerable: 0.14.0, 0.14.1, 0.15.0
It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had a uninitialized memory bug when building arrays with null values in some cases. This can lead to un…
- CVE-2019-12410HIGHCVSS 7.5EG 7.5✓ Fixed in 0.15.12019-11-08
vulnerable: 0.12.0 ... 0.15.0 (6 versions)
While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory Array data uninitialized when reading RLE null data from parquet. This affected the C++, Py…
- CVE-2023-47248CRITICALCVSS 9.8EG 9.8✓ Fixed in 14.0.12023-11-09
vulnerable: 0.14.0 ... 9.0.0 (26 versions)
Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (for exam…
- CVE-2024-52338CRITICALCVSS 9.8EG 9.8✓ Fixed in 17.0.02024-11-28
vulnerable: 10.0.0 ... 9.0.0 (22 versions)
Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from un…
- CVE-2026-25087HIGHCVSS 7.0EG 7.0✓ Fixed in 23.0.12026-02-17
vulnerable: 15.0.0 ... 23.0.0 (14 versions)
Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) with pre-buffering enabled, if the IPC file conta…
Check whether pyarrow is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for pyarrow CVEs against the assets you own.
Start Free Scan →