“A maximum severity remote code execution (RCE) vulnerability has been discovered impacting all versions of Apache Parquet up to and including 1.15.0.”

Apache Parquet has a maximum-severity code execution bug in every version through 1.15.0. Netflix, Uber, and the big cloud data lakes all run it. Exploiting it requires a malicious Parquet file. Data pipelines ingest outside Parquet files all day.