Repository navigation
Replies: 1 comment
|
The CVE isn't related to the Apache.Arrow NuGet package because it doesn't use the Apache Arrow C++ implementation. The CVE is for the Apache Arrow C++ implementation not .NET implementation. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Our Azure.Storage.Blobs package has taken a recent dependency on the Apache.Arrow Nuget package, and we received a Github Issue in regards to the 22.1.0 version being flagged as having a vulnerable dependency.
Azure/azure-sdk-for-net#63587
We were wondering if the nuget packages were at all affected by the recent reported CVE and if so, what version fixes the CVE.
I assumed the CVE was related to this.
GHSA-rgxp-2hwp-jwgg
https://arrow.apache.org/blog/2026/02/16/23.0.1-release/
Thanks in advance!
All reactions