Junglewise Threat Intelligence

CVE-2026-25087: Apache Arrow C++ use-after-free in IPC file reader

CVE-2026-25087 · Severity: high · CVSS 7 · Published 2026-02-17

Technologies: pyarrow (PyPI). Vendors: PyPI, Apache.

Executive brief

Apache Arrow is a development platform for in-memory data processing. A vulnerability in its C++ library could allow a specially crafted data file to cause the application to crash or experience memory corruption. This occurs when the library is configured to use a specific performance-enhancing feature called 'pre-buffering' while reading certain types of data files. While primarily a risk for service availability (denial of service), it could theoretically lead to more complex security issues depending on how the application manages memory.

Technical details

A use-after-free vulnerability exists in Apache Arrow C++ versions 15.0.0 through 23.0.0. The flaw is triggered when reading Arrow Inter-Process Communication (IPC) files containing variadic buffers (such as Binary View or String View data) while the 'pre-buffering' feature is enabled via the RecordBatchFileReader::PreBufferMetadata API. Under specific multi-threaded I/O timing conditions, the library may attempt to write a shared_ptr to a dangling pointer. While the attacker does not have direct control over the value written, the resulting memory corruption can lead to a denial of service (crash). This vulnerability specifically affects the C++ implementation; higher-level language bindings like Python (PyArrow), Ruby, and C GLib are not affected as they do not expose the vulnerable API. The issue is resolved in version 23.0.1.

Affected products

  • Apache Arrow C++ 15.0.0 through 23.0.0

Timeline

  • 2026-01-26: patched: Fix merged into main branch
  • 2026-02-17: disclosed: Public disclosure and CVE assignment

References

Related threats