CVE-2025-33042
published 2026-02-13CVE-2025-33042: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas…
PriorityP349high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.60%
44.6th percentile
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas.
This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0.
Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | avro | < 1.11.5 | 1.11.5 |
| apache | avro | — | — |
| apache_software_foundation | apache_avro_java_sdk | <= 1.11.4 | — |
| apache_software_foundation | apache_avro_java_sdk | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache Avro Java SDK up to 1.11.4/1.12.0 Schema Record Generator code injection (Nessus ID 310114)
vuldb·2026-04-25·CVSS 7.3
CVE-2025-33042 [HIGH] Apache Avro Java SDK up to 1.11.4/1.12.0 Schema Record Generator code injection (Nessus ID 310114)
A vulnerability classified as critical has been found in Apache Avro Java SDK up to 1.11.4/1.12.0. Affected by this issue is some unknown functionality of the component Schema Record Generator. This manipulation causes code injection.
This vulnerability is handled as CVE-2025-33042. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
GHSA
Apache Avro Java SDK is Vulnerable to Code Injection
ghsa·2026-02-13
CVE-2025-33042 [MEDIUM] CWE-94 Apache Avro Java SDK is Vulnerable to Code Injection
Apache Avro Java SDK is Vulnerable to Code Injection
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas.
This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0.
Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue.
OSV
Apache Avro Java SDK is Vulnerable to Code Injection
osv·2026-02-13
CVE-2025-33042 [MEDIUM] Apache Avro Java SDK is Vulnerable to Code Injection
Apache Avro Java SDK is Vulnerable to Code Injection
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas.
This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0.
Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue.
Red Hat
org.apache.avro/avro: Apache Avro Java SDK: Code injection on Java generated code
vendor_redhat·2026-02-13·CVSS 7.3
CVE-2025-33042 [HIGH] CWE-94 org.apache.avro/avro: Apache Avro Java SDK: Code injection on Java generated code
org.apache.avro/avro: Apache Avro Java SDK: Code injection on Java generated code
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas.
This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0.
Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue.
A code injection flaw has been discovered in Apache Avro. This vulnerability manifests when generating specific records from untrusted Avro schemas.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or s
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-33042 python-avro: Apache Avro Java SDK: Code injection on Java generated code [fedora-43]
bugzilla·2026-02-13·CVSS 7.3
CVE-2025-33042 [HIGH] CVE-2025-33042 python-avro: Apache Avro Java SDK: Code injection on Java generated code [fedora-43]
CVE-2025-33042 python-avro: Apache Avro Java SDK: Code injection on Java generated code [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This CVE affects the Apache Avro Java SDK only.
This package provides the Python implementation of Apache Avro,
which does not share the vulnerable Java code.
Bugzilla
CVE-2025-33042 ceph: Apache Avro Java SDK: Code injection on Java generated code [fedora-42]
bugzilla·2026-02-13·CVSS 7.3
CVE-2025-33042 [HIGH] CVE-2025-33042 ceph: Apache Avro Java SDK: Code injection on Java generated code [fedora-42]
CVE-2025-33042 ceph: Apache Avro Java SDK: Code injection on Java generated code [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, chan
Bugzilla
CVE-2025-33042 python-avro: Apache Avro Java SDK: Code injection on Java generated code [fedora-42]
bugzilla·2026-02-13·CVSS 7.3
CVE-2025-33042 [HIGH] CVE-2025-33042 python-avro: Apache Avro Java SDK: Code injection on Java generated code [fedora-42]
CVE-2025-33042 python-avro: Apache Avro Java SDK: Code injection on Java generated code [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This CVE affects the Apache Avro Java SDK only.
This package provides the Python implementation of Apache Avro,
which does not share the vulnerable Java code.
Wiz
CVE-2025-33042 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.3
CVE-2025-33042 [HIGH] CVE-2025-33042 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-33042 :
Java vulnerability analysis and mitigation
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas.
This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0.
Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue.
Source : NVD
## 7.3
Score
Published February 13, 2026
Severity HIGH
CNA Score 7.3
Affected Technologies
Java
NixOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 22.5
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
apache-pulsar
logstash-9.1
Sources
NVD
Alpine 3.18, 3.1
2026-02-13
Published