CVE-2025-27821: HDFS native client: Out of bounds write in URI parser of native HDFS client
Published Jan 23, 2026
·Updated
Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client.
This issue affects Apache Hadoop: from 3.2.0 before 3.4.2.
Users are recommended to upgrade to version 3.4.2, which fixes the issue.
Affected Software
3 affected componentsFixes available
Apache Hadoop>=3.2.0<3.4.2
maven/org.apache.hadoop:hadoop-hdfs-native-client>=3.2.0<3.4.2
3.4.2
Apache Hadoop>=3.2.0<3.4.2
Event History
Jan 26, 2026
CVE Published
via MITRE·09:44 AM
Data Sourced
via MITRE·09:44 AM
DescriptionWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·12:30 PM
Data Sourced
via GitHub·12:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-27821?
CVE-2025-27821 is classified as a high severity out-of-bounds write vulnerability in the Apache Hadoop HDFS native client.
2
How do I fix CVE-2025-27821?
To fix CVE-2025-27821, upgrade Apache Hadoop from any version between 3.2.0 and before 3.4.2 to version 3.4.2 or later.
3
Which versions of Apache Hadoop are affected by CVE-2025-27821?
CVE-2025-27821 affects Apache Hadoop versions from 3.2.0 up to and including versions before 3.4.2.
4
What components does CVE-2025-27821 impact?
CVE-2025-27821 impacts the native HDFS client of Apache Hadoop.
5
Is there a workaround for CVE-2025-27821?
There are no official workarounds for CVE-2025-27821; the recommended action is an upgrade to the patched version.