Arrow
Apache · 5 CVEs
CVE-2026-25087
HIGH
Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering
Feb 17, 2026
CVE-2024-52338
CRITICAL
Apache Arrow R package: Arbitrary code execution when loading a malicious data file
Nov 28, 2024
CVE-2024-41178
MEDIUM
Apache Arrow Rust Object Store: AWS WebIdentityToken exposure in log files
Jul 23, 2024
CVE-2019-12408
HIGH
It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow…
Nov 8, 2019
CVE-2019-12410
HIGH
While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0…
Nov 8, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-25087 | Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering | HIGH | 0.82% | Feb 17, 2026 |
| CVE-2024-52338 | Apache Arrow R package: Arbitrary code execution when loading a malicious data file | CRITICAL | 2.31% | Nov 28, 2024 |
| CVE-2024-41178 | Apache Arrow Rust Object Store: AWS WebIdentityToken exposure in log files | MEDIUM | 0.71% | Jul 23, 2024 |
| CVE-2019-12408 | It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had a uninitialized mem… | HIGH | 3.25% | Nov 8, 2019 |
| CVE-2019-12410 | While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory Array data… | HIGH | 4.61% | Nov 8, 2019 |
Showing 1 to 5 of 5 CVEs