CVE-2025-30065: A Ticking Time Bomb in Apache Parquet

Red | Vulnerability Report
Download PDF

A critical remote code execution (RCE) vulnerability, tracked as CVE-2025-30065 with a maximum CVSS score of 10.0, has been uncovered in all versions of the Apache Parquet Java library. This flaw could allow attackers to gain full control over a system simply by tricking it into processing a maliciously crafted Parquet file. Once exploited, the vulnerability could let attackers execute arbitrary code, steal or manipulate sensitive data, and install malware undetected. Given the severity of the issue, users are strongly urged to upgrade to Apache Parquet version 1.15.1, which addresses and resolves the flaw.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox