Back to Vulnerability Directory
HIGHFixed upstream
CVE-2025-27821
Apache Hadoop HDFS native client: out-of-bounds write in the URI parser
Technology
Apache Hadoop
CVSS Score
7.3 / 10.0
Affected Versions
3.2.0 to 3.4.1
Upstream Fix
3.4.2
Published
January 26, 2026
OSSeva Coverage
Fixed upstream
Is your Apache Hadoop deployment affected?
If you're running 3.2.0 to 3.4.1, you need this patch. Book a discovery call to get covered.