krivanekm-sap opened a new issue, #49089:
URL: https://github.com/apache/arrow/issues/49089

   ### Describe the bug, including details regarding any error messages, 
version, and platform.
   
   Hi PyArrow team,
   
   Our scanners are reporting high-severity vulnerabilities in the statically 
linked OpenSSL in `libarrow.so`, such as 
[CVE-2025-15467](https://nvd.nist.gov/vuln/detail/CVE-2025-15467) with [CVSS 
3.1 Base Score: 
9.8](https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2025-15467&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&version=3.1&source=CISA-ADP)
 and [11 
more](https://aisle.com/blog/aisle-discovered-12-out-of-12-openssl-vulnerabilities).
   
   Would it be possible to update it to version 3.5.5 or higher as suggested 
here, please?
   > OpenSSL 3.5 users should upgrade to OpenSSL 3.5.5.
   
   https://openssl-library.org/news/secadv/20260127.txt
   
   Thanks,
   Milan
   
   ### Component(s)
   
   Other


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to