CVE-2025-30065

CRITICAL

Apache Parquet <1.15.1 - RCE

Title source: llm

Description

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.

Exploits (6)

nomisec WORKING POC 12 stars
by bjornhels · poc
https://github.com/bjornhels/CVE-2025-30065
nomisec WORKING POC 12 stars
by F5-Labs · poc
https://github.com/F5-Labs/parquet-canary-exploit-rce-poc-CVE-2025-30065
nomisec WORKING POC 7 stars
by h3st4k3r · poc
https://github.com/h3st4k3r/CVE-2025-30065
nomisec WORKING POC 3 stars
by mouadk · poc
https://github.com/mouadk/parquet-rce-poc-CVE-2025-30065
nomisec WORKING POC 1 stars
by ThreatRadarAI · poc
https://github.com/ThreatRadarAI/TRAI-001-Critical-RCE-Vulnerability-in-Apache-Parquet-CVE-2025-30065-Simulation
nomisec WORKING POC
by ron-imperva · poc
https://github.com/ron-imperva/CVE-2025-30065-PoC

Scores

CVSS v3 9.8
EPSS 0.0051
EPSS Percentile 66.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (2)

apache/parquet_java < 1.15.1
org.apache.parquet/parquet-avro < 1.15.1Maven

Timeline

Published Apr 01, 2025
Tracked Since Feb 18, 2026