Open Source Security mailing list@oss_securityDisclosure
Apache Arrow has a disclosed use‑after‑free vulnerability when reading IPC files with pre‑buffering enabled; no PoC, exploit, or patch details are provided.
CVE@CVEnewGeneral
A use‑after‑free flaw in Apache Arrow C++ (15.0.0–23.0.0) triggered by reading an Arrow IPC file; no PoC, exploit, patch or active exploitation is mentioned.
Cyberwatcher_@cyberwatcher_Disclosure
A use‑after‑free vulnerability in Apache Arrow C++ (CVE‑2026‑25087) is announced, posing a privilege escalation risk.
CRAC Learning - Tech@cracbotDisclosure
The post announces CVE-2026-25087, a use‑after‑free vulnerability in Apache Arrow C++ with CVSS 7.0, affecting versions 15.0.0 through 23.0.0, and directs readers to the NVD entry.
emi.@r00tk1dXDisclosure
Apache announced CVE-2026-25087, a crash bug in Apache Arrow triggered by specially crafted files.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The post announces a use-after-free vulnerability in Apache Arrow’s C++ IPC File Reader, providing only the vulnerability type and a link to details, without any PoC, exploit, or patch information.