Avro
This hub aggregates every CVE we track for Avro, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
10
CVEs tracked
0
Critical
10
High
0
In CISA KEV
Severity distribution
HIGH10
Monthly trend
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
2
0
0
0
2024-092026-08
Latest CVEs
The 10 most recently published vulnerabilities affecting Avro.
- CVE-2026-46385iskorotkov/avro: CPU Exhaustion in Avro Decoder7.5
- CVE-2026-46384iskorotkov/avro: Integer Overflow in Avro Decoder7.5
- CVE-2025-33042Apache Avro Java SDK: Code injection on Java generated code7.3
- CVE-2024-47561Apache Avro Java SDK: Arbitrary Code Execution when reading Avro schema (Java SDK)7.3
- CVE-2023-39410Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDK7.5
- CVE-2023-37475Attacker-controlled parameter can cause denial of service in hamba avro7.5
- CVE-2022-36125Integer overflow when reading corrupted .avro file in Avro Rust SDK7.5
- CVE-2022-36124Memory overconsumption in Avro Rust SDK7.5
- CVE-2022-35724Denial of service while reading data in Avro Rust SDK7.5
- CVE-2021-43045Possible DOS vulnerabilities in C# Avro SDK7.5
Product normalization is registry-driven with AI assist and human review. How it works