Description
Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client.
This issue affects Apache Hadoop: from 3.2.0 before 3.4.2.
Users are recommended to upgrade to version 3.4.2, which fixes the issue.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: Low
Availability: Low
Affected Packages3 packages
🔴Vulnerability Details
3GHSAApache Hadoop HDFS Native Client has Out-of-bounds Write Vulnerability↗2026-01-26 ▶ OSVApache Hadoop HDFS Native Client has Out-of-bounds Write Vulnerability↗2026-01-26 ▶ CVEListHDFS native client: Out of bounds write in URI parser of native HDFS client↗2026-01-26 ▶ 📋Vendor Advisories
1ApacheApache hadoop: CVE-2025-27821↗ ▶ 🕵️Threat Intelligence
1WizCVE-2025-27821 Impact, Exploitability, and Mitigation Steps | Wiz↗ ▶