Skip to content

Upgrade avro to 1.12.1 to address CVE-2025-33042#25787

Closed
dao-jun wants to merge 1 commit into
apache:masterfrom
dao-jun:dep/upgrade_avro
Closed

Upgrade avro to 1.12.1 to address CVE-2025-33042#25787
dao-jun wants to merge 1 commit into
apache:masterfrom
dao-jun:dep/upgrade_avro

Conversation

@dao-jun
Copy link
Copy Markdown
Member

@dao-jun dao-jun commented May 15, 2026

Main Issue: #xyz

Motivation

Upgrade avro to 1.12.1 to address CVE-2025-33042

Modifications

Upgrade avro to 1.12.1

Verifying this change

  • Make sure that the change passes the CI checks.

(Please pick either of the following options)

This change is a trivial rework / code cleanup without any test coverage.

(or)

This change is already covered by existing tests, such as (please describe tests).

(or)

This change added tests and can be verified as follows:

(example:)

  • Added integration tests for end-to-end deployment with large payloads (10MB)
  • Extended integration test for recovery after broker failure

Does this pull request potentially affect one of the following parts:

If the box was checked, please highlight the changes

  • Dependencies (add or upgrade a dependency)
  • The public API
  • The schema
  • The default values of configurations
  • The threading model
  • The binary protocol
  • The REST endpoints
  • The admin CLI options
  • The metrics
  • Anything that affects deployment

@lhotari
Copy link
Copy Markdown
Member

lhotari commented May 15, 2026

duplicates #24992 which is blocked by https://issues.apache.org/jira/browse/AVRO-4209

@lhotari lhotari closed this May 15, 2026
@dao-jun dao-jun deleted the dep/upgrade_avro branch May 15, 2026 12:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants