CVE-2025-30065
CRITICALApache Parquet <1.15.1 - RCE
Title source: llmDescription
Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.
Exploits (6)
nomisec
WORKING POC
12 stars
by F5-Labs · poc
https://github.com/F5-Labs/parquet-canary-exploit-rce-poc-CVE-2025-30065
nomisec
WORKING POC
3 stars
by mouadk · poc
https://github.com/mouadk/parquet-rce-poc-CVE-2025-30065
nomisec
WORKING POC
1 stars
by ThreatRadarAI · poc
https://github.com/ThreatRadarAI/TRAI-001-Critical-RCE-Vulnerability-in-Apache-Parquet-CVE-2025-30065-Simulation
References (8)
Scores
CVSS v3
9.8
EPSS
0.0051
EPSS Percentile
66.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (2)
apache/parquet_java
< 1.15.1
org.apache.parquet/parquet-avro
< 1.15.1Maven
Timeline
Published
Apr 01, 2025
Tracked Since
Feb 18, 2026