pyarrow vulnerabilities
CVEs whose affected-version data names the pyarrow package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-25087High· 7.0Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering
Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering
▾ Twilightpyarrow · pyarrowEPSS 0.82%via OSV
CVE-2023-47248Critical· 9.8PoCPyArrow: Arbitrary code execution when loading a malicious data file
PyArrow: Arbitrary code execution when loading a malicious data file
▾ Abyssalpyarrow · pyarrowEPSS 15%via OSV