⚠ This page is served via a proxy. Original site: https://github.com
This service does not collect credentials or authentication data.
Skip to content

[parquet-hadoop] CVE-2025-67721 in io.airlift:[email protected] (migrate to aircompressor-v3?) #3387

@tlopesPT

Description

@tlopesPT

A vulnerability (medium or high depending on source) has been published affecting all versions of aircompressor except 3.4.
https://www.cve.org/CVERecord?id=CVE-2025-67721

Parquet-hadoop 1.16.0 uses 2.0.2 which is the latest release on that location, since the next major was released under aircompressor-v3

https://mvnrepository.com/artifact/io.airlift/aircompressor
https://mvnrepository.com/artifact/io.airlift/aircompressor-v3

There's an open PR to backport the CVE fix to a potential 2.0.3 but it's unclear if this will be picked up airlift/aircompressor#309.

Are there plans to migrate to aircompressor-v3?
Or any information if parquet-hadoop is unaffected by this vulnerability? My understanding is that writers using UNCOMPRESSED (default) are not affected.

Best regards,
Tiago

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions