Skip to content

[FLINK-39542] Upgrade avro to 1.11.5 that patches CVE-2025-33042#28034

Merged
snuyanzin merged 1 commit into
apache:masterfrom
Samrat002:FLINK-39542
Apr 27, 2026
Merged

[FLINK-39542] Upgrade avro to 1.11.5 that patches CVE-2025-33042#28034
snuyanzin merged 1 commit into
apache:masterfrom
Samrat002:FLINK-39542

Conversation

@Samrat002
Copy link
Copy Markdown
Contributor

What is the purpose of the change

Address to CVE-2025-33042

Brief change log

Upgrade avro to 1.11.5

Verifying this change

Existing UT and IT

Does this pull request potentially affect one of the following parts:

  • Dependencies (does it add or upgrade a dependency): yes
  • The public API, i.e., is any changed class annotated with @Public(Evolving): no
  • The serializers: no
  • The runtime per-record code paths (performance sensitive): no
  • Anything that affects deployment or recovery: JobManager (and its components), Checkpointing, Kubernetes/Yarn, ZooKeeper: no
  • The S3 file system connector: no

Documentation

  • Does this pull request introduce a new feature?no
  • If yes, how is the feature documented? not applicable

Was generative AI tooling used to co-author this PR?

No

@flinkbot
Copy link
Copy Markdown
Collaborator

flinkbot commented Apr 26, 2026

CI report:

Bot commands The @flinkbot bot supports the following commands:
  • @flinkbot run azure re-run the last Azure build

@github-actions github-actions Bot added the community-reviewed PR has been reviewed by the community. label Apr 26, 2026
@snuyanzin snuyanzin merged commit f55a280 into apache:master Apr 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

community-reviewed PR has been reviewed by the community.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants