AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-39410

HIGH · CVSS 7.5 EPSS 1.77%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-09-29 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It affects Apache, Java.

CVE
CVE-2023-39410
Severity
HIGH
CVSS
7.5
EPSS
1.77%
Apache Java

Original NVD Description

When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)