CVE-2025-30065

CRITICAL LAB

Apache Parquet <1.15.1 - RCE

Title source: llm

Description

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.

Exploits (7)

nomisec WORKING POC 12 stars
by F5-Labs · poc
https://github.com/F5-Labs/parquet-canary-exploit-rce-poc-CVE-2025-30065
nomisec WORKING POC 12 stars
by bjornhels · poc
https://github.com/bjornhels/CVE-2025-30065
nomisec WORKING POC 7 stars
by h3st4k3r · poc
https://github.com/h3st4k3r/CVE-2025-30065
nomisec WORKING POC 3 stars
by mouadk · poc
https://github.com/mouadk/parquet-rce-poc-CVE-2025-30065
nomisec WORKING POC 1 stars
by ThreatRadarAI · poc
https://github.com/ThreatRadarAI/TRAI-001-Critical-RCE-Vulnerability-in-Apache-Parquet-CVE-2025-30065-Simulation
nomisec WORKING POC
by micrictor · poc
https://github.com/micrictor/parquet-avro-rce
nomisec WORKING POC
by ron-imperva · poc
https://github.com/ron-imperva/CVE-2025-30065-PoC

Scores

CVSS v3 9.8
EPSS 0.0051
EPSS Percentile 66.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (2)
apache/parquet_java < 1.15.1
org.apache.parquet/parquet-avro 0 - 1.15.1Maven
Published Apr 01, 2025
Tracked Since Feb 18, 2026