Back to Vulnerability Directory
HIGHFixed upstream

CVE-2025-27821

Apache Hadoop HDFS native client: out-of-bounds write in the URI parser

Technology

Apache Hadoop

CVSS Score

7.3 / 10.0

Affected Versions

3.2.0 to 3.4.1

Upstream Fix

3.4.2

Published

January 26, 2026

OSSeva Coverage

Fixed upstream

Description

An out-of-bounds write in the URI parser of the Apache Hadoop HDFS native client can corrupt memory. It is tracked as HDFS-17754 and was announced in January 2026. Hadoop 3.2 and 3.3 have no fixed release. The 7.3 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache Hadoop deployment affected?

If you're running 3.2.0 to 3.4.1, you need this patch. Book a discovery call to get covered.