Junglewise Threat Intelligence

CVE-2026-42241: G-Research ParquetSharp stack overflow in DecimalConverter

CVE-2026-42241 · Severity: medium · CVSS 5.3 · Published 2026-04-24

Vendors: NuGet.

Executive brief

ParquetSharp, a library used for reading and writing Apache Parquet data files, is vulnerable to a denial-of-service attack. An attacker can provide a specially crafted Parquet file with an excessively large decimal column width, which causes the application to crash due to a stack overflow. This can lead to service outages for any application or network service that processes untrusted Parquet files.

Technical details

The vulnerability exists in the `DecimalConverter.ReadDecimal` method of ParquetSharp. The component uses the `stackalloc` keyword to allocate memory on the stack based on a width value provided within the Parquet file's metadata. Because this value is not properly validated, an attacker can specify an unreasonable width in a malicious Parquet file, triggering a stack overflow exception. This is a remote, unauthenticated attack vector (CWE-789) that results in a process crash (Denial of Service). The issue is fixed in version 23.0.0.1.

Affected products

  • G-Research ParquetSharp >= 18.1.0, < 23.0.0.1

Timeline

  • 2026-04-21: disclosed: Initial disclosure by reporter
  • 2026-04-24: advisory: GitHub Advisory published
  • 2026-04-24: patched: Version 23.0.0.1 released

References