Is there any official statement on CVE-2025-30065 (Apache Parquet vulnerability) for ADF, Microsoft Fabric or Synapse

Carla Villegas Pasco 0 Reputation points
2025-05-09T09:45:04.5666667+00:00

We've been inspecting Parquet/Delta Parquet metadata from files generated on Fabric and ADF, and can confirm, these services use Parquet version 1.13.1, which is vulnerable to CVE-2025-30065.

Has there been any official confirmation/acknowledgment from Microsoft on whether these services are affected, and if so, how to mitigate a potential exploit?

Azure Data Factory
Azure Data Factory
An Azure service for ingesting, preparing, and transforming data at scale.
11,510 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Venkat Reddy Navari 1,855 Reputation points Microsoft External Staff Moderator
    2025-05-09T11:27:14.6033333+00:00

    Hi @Carla Villegas PascoThank you for raising this important security concern.

    We are aware of CVE-2025-30065, which affects certain versions of the Apache Parquet library, including version 1.13.1, due to a vulnerability in how metadata is handled.

    At this time, Microsoft has not yet released a public security advisory specifically addressing the impact of this CVE on Azure Data Factory (ADF), Microsoft Fabric, or Azure Synapse Analytics.

    Current Guidance

    • Microsoft continuously evaluates and patches any third-party library vulnerabilities (including Apache libraries) used in our managed services.
    • If there is confirmed impact, Microsoft typically publishes advisories via:
    • For now, we recommend keeping an eye on the MSRC site and Azure updates for any official statement.
    • If your organization has heightened exposure or regulatory needs, you may raise a support ticket through the Azure Portal to get an official position under NDA from Microsoft support or the product team.

    I hope this information helps. Please do let us know if you have any further queries.

    Kindly consider upvoting the comment if the information provided is helpful. This can assist other community members in resolving similar issues.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.