-
Notifications
You must be signed in to change notification settings - Fork 4k
Open
Description
Hi PyArrow team,
Our scanners are reporting high-severity vulnerabilities in the statically linked OpenSSL in libarrow.so, such as CVE-2025-15467 with CVSS 3.1 Base Score: 9.8 and 11 more.
Would it be possible to update it to version 3.5.5 or higher as suggested here, please?
OpenSSL 3.5 users should upgrade to OpenSSL 3.5.5.
https://openssl-library.org/news/secadv/20260127.txt
Thanks,
Milan
Component(s)
Other