CVE-2026-25087Disclosure(apache / arrow)

LOWCVSS 7.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) with pre-buffering enabled, if the IPC file contains data with variadic buffers (such as Binary View and String View data). Depending on the number of variadic buffers in a record batch column and on the temporal sequence of multi-threaded IO, a write to a dangling pointer could occur. The value (a `std::shared_ptr<Buffer>` object) that is written to the dangling pointer is not under direct control of the attacker. Pre-buffering is disabled by default but can be enabled using a specific C++ API call (`RecordBatchFileReader::PreBufferMetadata`). The functionality is not exposed in language bindings (Python, Ruby, C GLib), so these bindings are not vulnerable. The most likely consequence of this issue would be random crashes or memory corruption when reading specific kinds of IPC files. If the application allows ingesting IPC files from untrusted sources, this could plausibly be exploited for denial of service. Inducing more targeted kinds of misbehavior (such as confidential data extraction from the running process) depends on memory allocation and multi-threaded IO temporal patterns that are unlikely to be easily controlled by an attacker. Advice for users of Arrow C++: 1. check whether you enable pre-buffering on the IPC file reader (using `RecordBatchFileReader::PreBufferMetadata`) 2. if so, either disable pre-buffering (which may have adverse performance consequences), or switch to Arrow 23.0.1 which is not vulnerable

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • arrow

Threat summary

  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-02-17); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
arrow

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-02-17: 2Mentions · 2026-02-18: 1Mentions · 2026-02-20: 1Mentions · 2026-02-22: 1Mentions · 2026-02-23: 1Technical Details · 2026-02-17: 2Technical Details · 2026-02-18: 1Technical Details · 2026-02-20: 1Technical Details · 2026-02-22: 1Technical Details · 2026-02-23: 102-1702-1802-2002-2202-23
Signal classification2 categories
Disclosure
583.3%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-172
Disclosure1General1
2026-02-181
Disclosure1
2026-02-201
Disclosure1
2026-02-221
Disclosure1
2026-02-231
Disclosure1
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-25087: Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering https://www.openwall.com/lists/oss-security/2026/02/17/4 Pre-buffering is disabled by default but can be enabled using a specific C++ API call

    Post summary

    Apache Arrow has a disclosed use‑after‑free vulnerability when reading IPC files with pre‑buffering enabled; no PoC, exploit, or patch details are provided.

    00073600
    4.4K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-25087 Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file … https://www.cve.org/CVERecord?id=CVE-2026-25087

    Post summary

    A use‑after‑free flaw in Apache Arrow C++ (15.0.0–23.0.0) triggered by reading an Arrow IPC file; no PoC, exploit, patch or active exploitation is mentioned.

    00012290
    56.4K followersView on X
  • Cyberwatcher_@cyberwatcher_
    Disclosure

    Vulnérabilité Use After Free dans Apache Arrow C++ : risque d’élévation de privilèges. #Cybersecurity #InfoSec #Vulnerability https://cyberveille.esante.gouv.fr/alertes/apache-cve-2026-25087-2026-02-23

    Post summary

    A use‑after‑free vulnerability in Apache Arrow C++ (CVE‑2026‑25087) is announced, posing a privilege escalation risk.

    0000047
    11 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-25087 (CVSS:7.0, HIGH) is Awaiting Analysis. Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It ca..https://nvd.nist.gov/vuln/detail/CVE-2026-25087 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-25087, a use‑after‑free vulnerability in Apache Arrow C++ with CVSS 7.0, affecting versions 15.0.0 through 23.0.0, and directs readers to the NVD entry.

    0000082
    171 followersView on X
  • emi.@r00tk1dX
    Disclosure

    three days ago, the Apache Security team published CVE-2026-25087 for my research affecting Apache Arrow. the issue can cause the application to crash when processing certain specially crafted files. https://www.cve.org/CVERecord?id=CVE-2026-25087

    Post summary

    Apache announced CVE-2026-25087, a crash bug in Apache Arrow triggered by specially crafted files.

    0000034
    19 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25087 Use After Free Vulnerability in Apache Arrow C++ IPC File Reader ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25087 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The post announces a use-after-free vulnerability in Apache Arrow’s C++ IPC File Reader, providing only the vulnerability type and a link to details, without any PoC, exploit, or patch information.

    0000047
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachearrow---

Explore more