CVE-2025-33042

CWE-94Code Injection6 documents6 sources
Severity
7.3HIGH
EPSS
0.1%
top 82.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 13

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4

Affected Packages3 packages

NVDapache/avro< 1.11.5+1
Mavenorg.apache.avro:avro-compiler1.12.01.12.1+1

🔴Vulnerability Details

3
CVEList
Apache Avro Java SDK: Code injection on Java generated code2026-02-13
GHSA
Apache Avro Java SDK is Vulnerable to Code Injection2026-02-13
OSV
Apache Avro Java SDK is Vulnerable to Code Injection2026-02-13

📋Vendor Advisories

1
Red Hat
org.apache.avro/avro: Apache Avro Java SDK: Code injection on Java generated code2026-02-13

🕵️Threat Intelligence

1
Wiz
CVE-2025-33042 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-33042 (HIGH CVSS 7.3) | Improper Control of Generation of C | cvebase.io