Executive brief
ParquetSharp, a library used for reading and writing Apache Parquet data files, is vulnerable to a denial-of-service attack. An attacker can provide a specially crafted Parquet file with an excessively large decimal column width, which causes the application to crash due to a stack overflow. This can lead to service outages for any application or network service that processes untrusted Parquet files.
Technical details
The vulnerability exists in the `DecimalConverter.ReadDecimal` method of ParquetSharp. The component uses the `stackalloc` keyword to allocate memory on the stack based on a width value provided within the Parquet file's metadata. Because this value is not properly validated, an attacker can specify an unreasonable width in a malicious Parquet file, triggering a stack overflow exception. This is a remote, unauthenticated attack vector (CWE-789) that results in a process crash (Denial of Service). The issue is fixed in version 23.0.0.1.
Affected products
- G-Research ParquetSharp >= 18.1.0, < 23.0.0.1
Timeline
- 2026-04-21: disclosed: Initial disclosure by reporter
- 2026-04-24: advisory: GitHub Advisory published
- 2026-04-24: patched: Version 23.0.0.1 released