Intel

AIKIDO-2026-10110

github.com/apache/arrow-go/v18 is vulnerable to Uncaught Exception

Uncaught Exception Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

25

Low Risk

This Affects:

GOgithub.com/apache/arrow-go/v18
18.0.0 - 18.5.0
Fixed in 18.5.1

TL;DR

Affected versions of this package are vulnerable to multiple panic conditions, which can be triggered by malformed or specially crafted input and may result in unexpected application crashes.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges.

Background info

github.com/apache/arrow-go/v18 is vulnerable to Uncaught Exception in versions 18.0.0 - 18.5.0.

How to fix this

Upgrade the github.com/apache/arrow-go/v18 library to the patch version.

Background Info