{"id":"GHSA-3w5g-989p-35r8","summary":"Apache Avro Rust SDK corrupted data read can cause crash","details":"It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which addresses this issue.","aliases":["CVE-2022-36125"],"modified":"2026-03-06T22:40:31Z","published":"2022-08-10T00:00:31Z","database_specific":{"nvd_published_at":"2022-08-09T07:15:00Z","cwe_ids":["CWE-190","CWE-20"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-08-18T19:14:55Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-36125"},{"type":"PACKAGE","url":"https://github.com/a0x8o/avro"},{"type":"WEB","url":"https://lists.apache.org/thread/t1r5xz0pvhm4tosqopjpj6dz8zlsht07"}],"affected":[{"package":{"name":"apache-avro","ecosystem":"crates.io","purl":"pkg:cargo/apache-avro"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.14.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-3w5g-989p-35r8/GHSA-3w5g-989p-35r8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}