Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rrjr-v56m-ww88 | ParquetSharp: Possible Stack Overflow When Reading a ParquetFile with Large Decimal Type Width |
Fri, 08 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 07 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
G-research
G-research parquetsharp |
|
| Vendors & Products |
G-research
G-research parquetsharp |
Thu, 07 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ParquetSharp is a .NET library for reading and writing Apache Parquet files. From version 18.1.0 to before version 23.0.0.1, DecimalConverter.ReadDecimal makes a stackalloc using what might be an attacker-supplied value. If an attacker declares a decimal column with some unreasonable width, this could lead to a stack overflow. In a service environment, this would potentially take down a service. This affects applications using ParquetSharp to read untrusted Parquet files in a network service. This issue has been patched in version 23.0.0.1. | |
| Title | ParquetSharp: Possible Stack Overflow When Reading a ParquetFile with Large Decimal Type Width | |
| Weaknesses | CWE-789 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-08T21:30:27.110Z
Reserved: 2026-04-25T05:37:12.118Z
Link: CVE-2026-42241
Updated: 2026-05-08T14:38:31.554Z
Status : Deferred
Published: 2026-05-07T20:16:44.247
Modified: 2026-05-07T20:37:54.060
Link: CVE-2026-42241
No data.
OpenCVE Enrichment
Updated: 2026-05-07T21:24:24Z
Github GHSA