Intel

AIKIDO-2025-10342

arrow2 is vulnerable to Use of Unmaintained Third Party Components

Use of Unmaintained Third Party ComponentsGHSA-wv8j-m3hx-924j Published Jun 3, 2025

50

Medium Risk

This Affects:

rustarrow2
0.0.0 - *
Are you affected? Scan for Free

TL;DR

The method Rows::row_unchecked() allows out of bounds access to the underlying buffer without sufficient checks. The arrow2 crate is no longer maintained, so there are no plans to fix this issue.

Who does this affect?

You are affected if you are using this package.

Background info

arrow2 is vulnerable to Use of Unmaintained Third Party Components in all versions.

How to fix this

Remove any arrow2 package from your application. Please take a look at arrow instead.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform