cve-2025-33042
MEDIUM CVSS 5.6 csaf_redhat
Description
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
Timeline
- Published
- 2025-01-01 00:00 UTC
- Last Modified
- 2026-06-28
CVSS Details
CVSS details not available.
Affected Products
No product information available.
Weaknesses (CWE)
References
No references available.
Linked Vulnerabilities
{
"document": {
"aggregate_severity": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"text": "Moderate"
},
"category": "csaf_vex",
"csaf_version": "2.0",
"distribution": {
"text": "Copyright © Red Hat, Inc. All rights reserved.",
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "en",
"notes": [
{
"category": "legal_disclaimer",
"text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
"title": "Terms of Use"
}
],
"publisher": {
"category": "vendor",
"contact_details": "https://access.redhat.com/security/team/contact/",
"issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
"name": "Red Hat Product Security",
"namespace": "https://www.redhat.com"
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-33042.json"
}
],
"title": "org.apache.avro/avro: Apache Avro Java SDK: Code injection on Java generated code",
"tracking": {
"current_release_date": "2026-06-28T11:28:49+00:00",
"generator": {
"date": "2026-06-28T11:28:49+00:00",
"engine": {
"name": "Red Hat SDEngine",
"version": "5.2.6"
}
},
"id": "CVE-2025-33042",
"initial_release_date": "2025-01-01T00:00:00+00:00",
"revision_history": [
{
"date": "2025-01-01T00:00:00+00:00",
"number": "1",
"summary": "Initial version"
},
{
"date": "2026-03-16T08:31:19+00:00",
"number": "2",
"summary": "Current version"
},
{
"date": "2026-06-28T11:28:49+00:00",
"number": "3",
"summary": "Last generated version"
}
],
"status": "final",
"version": "3"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_name",
"name": "Red Hat build of Apache Camel 4 for Quarkus 3",
"product": {
"name": "Red Hat build of Apache Camel 4 for Quarkus 3",
"product_id": "red_hat_build_of_apache_camel_4_for_quarkus_3",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:camel_quarkus:3"
}
}
}
],
"category": "product_family",
"name": "Red Hat build of Apache Camel 4 for Quarkus 3"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat build of Apache Camel for Spring Boot 4",
"product": {
"name": "Red Hat build of Apache Camel for Spring Boot 4",
"product_id": "red_hat_build_of_apache_camel_for_spring_boot_4",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:camel_spring_boot:4"
}
}
}
],
"category": "product_family",
"name": "Red Hat build of Apache Camel for Spring Boot 4"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat build of Apicurio Registry 2",
"product": {
"name": "Red Hat build of Apicurio Registry 2",
"product_id": "red_hat_build_of_apicurio_registry_2",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:service_registry:2"
}
}
}
],
"category": "product_family",
"name": "Red Hat build of Apicurio Registry 2"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat build of Apicurio Registry 3",
"product": {
"name": "Red Hat build of Apicurio Registry 3",
"product_id": "red_hat_build_of_apicurio_registry_3",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:apicurio_registry:3"
}
}
}
],
"category": "product_family",
"name": "Red Hat build of Apicurio Registry 3"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat build of Debezium 2",
"product": {
"name": "Red Hat build of Debezium 2",
"product_id": "red_hat_build_of_debezium_2",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:debezium:2"
}
}
}
],
"category": "product_family",
"name": "Red Hat build of Debezium 2"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat build of Debezium 3",
"product": {
"name": "Red Hat build of Debezium 3",
"product_id": "red_hat_build_of_debezium_3",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:debezium:3"
}
}
}
],
"category": "product_family",
"name": "Red Hat build of Debezium 3"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat Data Grid 8",
"product": {
"name": "Red Hat Data Grid 8",
"product_id": "red_hat_data_grid_8",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:jboss_data_grid:8"
}
}
}
],
"category": "product_family",
"name": "Red Hat Data Grid 8"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat Fuse 7",
"product": {
"name": "Red Hat Fuse 7",
"product_id": "red_hat_fuse_7",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:jboss_fuse:7"
}
}
}
],
"category": "product_family",
"name": "Red Hat Fuse 7"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat JBoss Enterprise Application Platform 7",
"product": {
"name": "Red Hat JBoss Enterprise Application Platform 7",
"product_id": "red_hat_jboss_enterprise_application_platform_7",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7"
}
}
}
],
"category": "product_family",
"name": "Red Hat JBoss Enterprise Application Platform 7"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat JBoss Enterprise Application Platform 8",
"product": {
"name": "Red Hat JBoss Enterprise Application Platform 8",
"product_id": "red_hat_jboss_enterprise_application_platform_8",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:8"
}
}
}
],
"category": "product_family",
"name": "Red Hat JBoss Enterprise Application Platform 8"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
"product": {
"name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
"product_id": "red_hat_jboss_enterprise_application_platform_expansion_pack",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:jbosseapxp"
}
}
}
],
"category": "product_family",
"name": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat Single Sign-On 7",
"product": {
"name": "Red Hat Single Sign-On 7",
"product_id": "red_hat_single_sign-on_7",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:red_hat_single_sign_on:7"
}
}
}
],
"category": "product_family",
"name": "Red Hat Single Sign-On 7"
},
{
"branches": [
{
"category": "product_name",
"name": "streams for Apache Kafka 2",
"product": {
"name": "streams for Apache Kafka 2",
"product_id": "streams_for_apache_kafka_2",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:amq_streams:2"
}
}
}
],
"category": "product_family",
"name": "streams for Apache Kafka 2"
},
{
"branches": [
{
"category": "product_name",
"name": "streams for Apache Kafka 3",
"product": {
"name": "streams for Apache Kafka 3",
"product_id": "streams_for_apache_kafka_3",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:amq_streams:3"
}
}
}
],
"category": "product_family",
"name": "streams for Apache Kafka 3"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat build of Quarkus 3.27.3",
"product": {
"name": "Red Hat build of Quarkus 3.27.3",
"product_id": "Red Hat build of Quarkus 3.27.3",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:quarkus:3.27::el8"
}
}
},
{
"category": "product_name",
"name": "Red Hat build of Quarkus 3.20.6",
"product": {
"name": "Red Hat build of Quarkus 3.20.6",
"product_id": "Red Hat build of Quarkus 3.20.6",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:quarkus:3.20::el8"
}
}
}
],
"category": "product_family",
"name": "Red Hat build of Quarkus"
},
{
"category": "product_version",
"name": "avro",
"product": {
"name": "avro",
"product_id": "avro",
"product_identification_helper": {
"purl": "pkg:maven/org.apache.avro/avro"
}
}
}
],
"category": "vendor",
"name": "Red Hat"
}
],
"relationships": [
{
"category": "default_component_of",
"full_product_name": {
"name": "avro as a component of Red Hat build of Apache Camel 4 for Quarkus 3",
"product_id": "red_hat_build_of_apache_camel_4_for_quarkus_3:avro"
},
"product_reference": "avro",
"relates_to_product_reference": "red_hat_build_of_apache_camel_4_for_quarkus_3"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "avro as a component of Red Hat build of Apache Camel for Spring Boot 4",
"product_id": "red_hat_build_of_apache_camel_for_spring_boot_4:avro"
},
"product_reference": "avro",
"relates_to_product_reference": "red_hat_build_of_apache_camel_for_spring_boot_4"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "avro as a component of Red Hat build of Apicurio Registry 2",
"product_id": "red_hat_build_of_apicurio_registry_2:avro"
},
"product_reference": "avro",
"relates_to_product_reference": "red_hat_build_of_apicurio_registry_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "avro as a component of Red Hat build of Apicurio Registry 3",
"product_id": "red_hat_build_of_apicurio_registry_3:avro"
},
"product_reference": "avro",
"relates_to_product_reference": "red_hat_build_of_apicurio_registry_3"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "avro as a component of Red Hat build of Debezium 2",
"product_id": "red_hat_build_of_debezium_2:avro"
},
"product_reference": "avro",
"relates_to_product_reference": "red_hat_build_of_debezium_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "avro as a component of Red Hat build of Debezium 3",
"product_id": "red_hat_build_of_debezium_3:avro"
},
"product_reference": "avro",
"relates_to_product_reference": "red_hat_build_of_debezium_3"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "avro as a component of Red Hat Data Grid 8",
"product_id": "red_hat_data_grid_8:avro"
},
"product_reference": "avro",
"relates_to_product_reference": "red_hat_data_grid_8"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "avro as a component of Red Hat Fuse 7",
"product_id": "red_hat_fuse_7:avro"
},
"product_reference": "avro",
"relates_to_product_reference": "red_hat_fuse_7"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "avro as a component of Red Hat JBoss Enterprise Application Platform 7",
"product_id": "red_hat_jboss_enterprise_application_platform_7:avro"
},
"product_reference": "avro",
"relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_7"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "avro as a component of Red Hat JBoss Enterprise Application Platform 8",
"product_id": "red_hat_jboss_enterprise_application_platform_8:avro"
},
"product_reference": "avro",
"relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_8"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "avro as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack",
"product_id": "red_hat_jboss_enterprise_application_platform_expansion_pack:avro"
},
"product_reference": "avro",
"relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_expansion_pack"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "avro as a component of Red Hat Single Sign-On 7",
"product_id": "red_hat_single_sign-on_7:avro"
},
"product_reference": "avro",
"relates_to_product_reference": "red_hat_single_sign-on_7"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "avro as a component of streams for Apache Kafka 2",
"product_id": "streams_for_apache_kafka_2:avro"
},
"product_reference": "avro",
"relates_to_product_reference": "streams_for_apache_kafka_2"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "avro as a component of streams for Apache Kafka 3",
"product_id": "streams_for_apache_kafka_3:avro"
},
"product_reference": "avro",
"relates_to_product_reference": "streams_for_apache_kafka_3"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2025-33042",
"cwe": {
"id": "CWE-94",
"name": "Improper Control of Generation of Code ('Code Injection')"
},
"discovery_date": "2026-02-13T12:00:45.349337+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2439675"
}
],
"notes": [
{
"category": "description",
"text": "A code injection flaw has been discovered in Apache Avro. This vulnerability manifests when generating specific records from untrusted Avro schemas.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "org.apache.avro/avro: Apache Avro Java SDK: Code injection on Java generated code",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat build of Quarkus 3.20.6",
"Red Hat build of Quarkus 3.27.3"
],
"known_affected": [
"red_hat_build_of_apache_camel_4_for_quarkus_3:avro",
"red_hat_build_of_apache_camel_for_spring_boot_4:avro",
"red_hat_build_of_apicurio_registry_2:avro",
"red_hat_build_of_apicurio_registry_3:avro",
"red_hat_build_of_debezium_2:avro",
"red_hat_build_of_debezium_3:avro",
"red_hat_data_grid_8:avro",
"red_hat_fuse_7:avro",
"red_hat_jboss_enterprise_application_platform_7:avro",
"red_hat_jboss_enterprise_application_platform_8:avro",
"red_hat_jboss_enterprise_application_platform_expansion_pack:avro",
"red_hat_single_sign-on_7:avro",
"streams_for_apache_kafka_2:avro",
"streams_for_apache_kafka_3:avro"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2025-33042"
},
{
"category": "external",
"summary": "RHBZ#2439675",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2439675"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2025-33042",
"url": "https://www.cve.org/CVERecord?id=CVE-2025-33042"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2025-33042",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33042"
},
{
"category": "external",
"summary": "https://github.com/apache/avro/commit/84bc7322ca1c04ab4a8e4e708acf1e271541aac4",
"url": "https://github.com/apache/avro/commit/84bc7322ca1c04ab4a8e4e708acf1e271541aac4"
},
{
"category": "external",
"summary": "https://issues.apache.org/jira/browse/AVRO-4053",
"url": "https://issues.apache.org/jira/browse/AVRO-4053"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/fy88wmgf1lj9479vrpt12cv8x73lroj1",
"url": "https://lists.apache.org/thread/fy88wmgf1lj9479vrpt12cv8x73lroj1"
},
{
"category": "external",
"summary": "https://www.openwall.com/lists/oss-security/2026/02/12/2",
"url": "https://www.openwall.com/lists/oss-security/2026/02/12/2"
}
],
"release_date": "2026-02-13T11:47:03.783000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-04-14T17:18:52+00:00",
"details": "Before applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258",
"product_ids": [
"Red Hat build of Quarkus 3.20.6"
],
"url": "https://access.redhat.com/errata/RHSA-2026:7109"
},
{
"category": "vendor_fix",
"date": "2026-04-14T14:45:52+00:00",
"details": "Before applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258",
"product_ids": [
"Red Hat build of Quarkus 3.27.3"
],
"url": "https://access.redhat.com/errata/RHSA-2026:7380"
},
{
"category": "workaround",
"details": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
"product_ids": [
"Red Hat build of Quarkus 3.20.6",
"Red Hat build of Quarkus 3.27.3",
"red_hat_build_of_apache_camel_4_for_quarkus_3:avro",
"red_hat_build_of_apache_camel_for_spring_boot_4:avro",
"red_hat_build_of_apicurio_registry_2:avro",
"red_hat_build_of_apicurio_registry_3:avro",
"red_hat_build_of_debezium_2:avro",
"red_hat_build_of_debezium_3:avro",
"red_hat_data_grid_8:avro",
"red_hat_fuse_7:avro",
"red_hat_jboss_enterprise_application_platform_7:avro",
"red_hat_jboss_enterprise_application_platform_8:avro",
"red_hat_jboss_enterprise_application_platform_expansion_pack:avro",
"red_hat_single_sign-on_7:avro",
"streams_for_apache_kafka_2:avro",
"streams_for_apache_kafka_3:avro"
]
},
{
"category": "none_available",
"details": "Fix deferred",
"product_ids": [
"red_hat_build_of_apache_camel_4_for_quarkus_3:avro",
"red_hat_build_of_apache_camel_for_spring_boot_4:avro",
"red_hat_build_of_apicurio_registry_2:avro",
"red_hat_build_of_apicurio_registry_3:avro",
"red_hat_build_of_debezium_2:avro",
"red_hat_build_of_debezium_3:avro",
"red_hat_data_grid_8:avro",
"red_hat_fuse_7:avro",
"red_hat_jboss_enterprise_application_platform_7:avro",
"red_hat_jboss_enterprise_application_platform_8:avro",
"red_hat_jboss_enterprise_application_platform_expansion_pack:avro",
"red_hat_single_sign-on_7:avro",
"streams_for_apache_kafka_2:avro",
"streams_for_apache_kafka_3:avro"
]
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.6,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
},
"products": [
"Red Hat build of Quarkus 3.20.6",
"Red Hat build of Quarkus 3.27.3",
"red_hat_build_of_apache_camel_4_for_quarkus_3:avro",
"red_hat_build_of_apache_camel_for_spring_boot_4:avro",
"red_hat_build_of_apicurio_registry_2:avro",
"red_hat_build_of_apicurio_registry_3:avro",
"red_hat_build_of_debezium_2:avro",
"red_hat_build_of_debezium_3:avro",
"red_hat_data_grid_8:avro",
"red_hat_fuse_7:avro",
"red_hat_jboss_enterprise_application_platform_7:avro",
"red_hat_jboss_enterprise_application_platform_8:avro",
"red_hat_jboss_enterprise_application_platform_expansion_pack:avro",
"red_hat_single_sign-on_7:avro",
"streams_for_apache_kafka_2:avro",
"streams_for_apache_kafka_3:avro"
]
}
],
"threats": [
{
"category": "impact",
"details": "Moderate",
"product_ids": [
"Red Hat build of Quarkus 3.20.6",
"Red Hat build of Quarkus 3.27.3",
"red_hat_build_of_apache_camel_4_for_quarkus_3:avro",
"red_hat_build_of_apache_camel_for_spring_boot_4:avro",
"red_hat_build_of_apicurio_registry_2:avro",
"red_hat_build_of_apicurio_registry_3:avro",
"red_hat_build_of_debezium_2:avro",
"red_hat_build_of_debezium_3:avro",
"red_hat_data_grid_8:avro",
"red_hat_fuse_7:avro",
"red_hat_jboss_enterprise_application_platform_7:avro",
"red_hat_jboss_enterprise_application_platform_8:avro",
"red_hat_jboss_enterprise_application_platform_expansion_pack:avro",
"red_hat_single_sign-on_7:avro",
"streams_for_apache_kafka_2:avro",
"streams_for_apache_kafka_3:avro"
]
}
],
"title": "org.apache.avro/avro: Apache Avro Java SDK: Code injection on Java generated code"
}
]
}
Enrichment data
Aggregated bundle (all enrichments)