Known Vulnerabilities for Avro by Apache
Listed below are 6 of the newest known vulnerabilities associated with "Avro" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-55415 json | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, ... | Not Provided | 2026-07-28 | 2026-07-29 |
| CVE-2026-55391 json | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, ... | Not Provided | 2026-07-28 | 2026-07-29 |
| CVE-2026-55389 json | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, ... | Not Provided | 2026-07-28 | 2026-07-29 |
| CVE-2026-54690 json | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, ... | Not Provided | 2026-07-28 | 2026-07-29 |
| CVE-2026-54656 json | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, ... | Not Provided | 2026-07-28 | 2026-07-29 |
| CVE-2026-54653 json | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, ... | Not Provided | 2026-07-28 | 2026-07-29 |
| CVE-2026-46385 json | iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-controlled ... | Not Provided | 2026-05-29 | 2026-07-30 |
| CVE-2026-46384 json | iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, several Avro decoder paths read attacker-controlled 64-bit values f... | Not Provided | 2026-05-29 | 2026-07-30 |
| CVE-2023-39410 json | When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints ... | 7.5 - HIGH | 2023-09-29 | 2023-10-06 |
| CVE-2022-36125 json | It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications... | 7.5 - HIGH | 2022-08-09 | 2022-08-12 |