Skip to content

GH-754: Remove incomplete, manually-maintained CVE list#764

Open
pitrou wants to merge 1 commit intoapache:mainfrom
pitrou:gh754-cve-list
Open

GH-754: Remove incomplete, manually-maintained CVE list#764
pitrou wants to merge 1 commit intoapache:mainfrom
pitrou:gh754-cve-list

Conversation

@pitrou
Copy link
Member

@pitrou pitrou commented Feb 25, 2026

No description provided.

@pitrou pitrou requested a review from alamb February 25, 2026 10:29
@github-actions
Copy link

Preview URL: https://pitrou.github.io/arrow-site

If the preview URL doesn't work, you may forget to configure your fork repository for preview.
See https://github.com/apache/arrow-site/blob/main/README.md#forks how to configure.

@pitrou pitrou requested a review from raboof February 25, 2026 10:29
Copy link
Contributor

@alamb alamb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me -- thank you @pitrou and @raboof


**Mitigation**: Upgrade to version 0.15.1 or greater.
For security advisories published before 2023, one can use
[a targeted search query](https://www.cve.org/CVERecord/SearchResults?query=%22Apache+Software+Foundation%22+%22arrow%22)
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I also checked that this link works as well 👍


### [CVE-2023-47248](https://www.cve.org/CVERecord?id=CVE-2023-47248): Arbitrary code execution when loading a malicious data file in PyArrow
For security advisories published since 2023, please refer to
[this page](https://security.apache.org/projects/arrow/) maintained by the Apache
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I verified this link is good

Image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants