NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Maven Central · #1309 by repository stars
Archetype that generates a simple example Avro service
Last release 1 months ago
18 Aug 2026
Ships fairly regularly
a new release about every 8 months
Rarely documented
notes for 1 of 30 stable releases
Nothing withdrawn
no release was ever pulled
15 years old
30 releases · first in 2011
AVRO-4196 : Package 'Microsoft.Build.Utilities.Core' 17.8.3 has a known high severity vulnerability
The Apache Avro community is pleased to announce the release of Avro 1.12.2!
All signed release artifacts, signatures and verification instructions can be found here
This release includes a broad round of hardening against malformed and adversarial input across the Java and Python SDKs (bounding allocations and enforcing decompression limits before trusting size fields read from the input), plus a handful of other fixes with security impact in C#, C++ and JavaScript:
The Avro 1.12.2 Java SDK now restricts arbitrary Java classes from being instantiated, either from the SpecificDatumReader or java-class attributes in a schema.
If you are not setting the org.apache.avro.SERIALIZABLE_CLASSES or org.apache.avro.SERIALIZABLE_PACKAGES system properties, you may experience the following java.lang.SecurityException:
java.lang.SecurityException: Forbidden com.example.MyCustomClass!
This class is not trusted to be included in Avro schemas.
at org.apache.avro.util.ClassSecurityValidator.validate(ClassSecurityValidator.java:60)
at org.apache.avro.util.ClassUtils.forName(ClassUtils.java:99)
...
See AVRO-4189 for more details.
The recommended action is to list the classes and packages that Avro is allowed to instantiate in the org.apache.avro.SERIALIZABLE_CLASSES or org.apache.avro.SERIALIZABLE_PACKAGES system properties.
If you are running Avro in an environment with trusted schemas and trusted data, you can restore the old behaviour by setting org.apache.avro.SERIALIZABLE_PACKAGES to *
(or calling ClassSecurityValidator.setGlobal(...) to trust your own classes).
These SDKs also picked up dependency and build-tooling updates with no other user-facing change: C#, C++, Java, JavaScript, Python.
Thanks to everyone for contributing!
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →