Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas.
This issue affects Apache Avro Java SDK: all versions through 1.11.4 and versionĀ 1.12.0.
Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue.
{
"sources": [
{
"imported": "2026-08-24T05:26:54.550Z",
"database_specific": {
"status": "Analyzed"
},
"affected": {
"apache:avro": [
"< 1.11.5",
"= 1.12.0-+-",
"= 1.12.0-rc0+-",
"= 1.12.0-rc1+-"
]
},
"id": "CVE-2025-33042",
"published": "2026-02-13T12:16:07.570Z",
"modified": "2026-06-17T09:13:00.170Z",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-33042",
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33042"
},
{
"imported": "2026-08-24T05:26:55.520Z",
"published": "2026-02-13T12:31:21Z",
"modified": "2026-06-05T14:25:54Z",
"id": "GHSA-rp46-r563-jrc7",
"html_url": "https://github.com/advisories/GHSA-rp46-r563-jrc7",
"url": "https://api.github.com/advisories/GHSA-rp46-r563-jrc7"
},
{
"imported": "2026-08-24T05:26:54.550Z",
"published": "2026-02-13T11:47:03Z",
"url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2025-206910",
"id": "EUVD-2025-206910",
"html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-206910",
"modified": "2026-02-13T18:05:35Z"
}
],
"license": "CC-BY-4.0"
}