This document outlines the security model for Apache DataFusion and how to report vulnerabilities.
This model also applies to the datafusion-cli command line tool, which is a thin wrapper around the DataFusion library.
DataFusion is a low level library, designed to be embedded in applications that have their own security model. This section describes DataFusion's own model: what counts as a bug versus a vulnerability.
In general, crashes, panics, hangs, and excessive resource consumption (memory, CPU, or disk) are treated as bugs, not vulnerabilities, unless they are exploitable and could let an attacker:
- Execute arbitrary code (Remote Code Execution), or
- Exfiltrate sensitive information from process memory (Information Disclosure).
If the exploitation path is unclear, please report the issue as a bug rather than a vulnerability. The sections below describe what DataFusion treats as trusted input in a few specific areas.
SQL and DataFrame queries are executable code, comparable to a scripting
language: a query can legitimately read files, open network connections
(e.g. via CREATE EXTERNAL TABLE), and consume significant CPU, memory, or
disk. Running such a query is not, on its own, a vulnerability.
It is the embedding application's responsibility to decide whether a query is
safe to run (e.g. validating externally supplied SQL text or URLs) and to
sandbox untrusted queries at the OS/container level if needed. APIs such as
SQLOptions::with_allow_dml can help restrict what a query is allowed to
do, but do not guarantee that all input is safe to execute.
Format readers (e.g. Parquet, CSV, JSON, Avro, and Arrow IPC) assume a well-formed file from a trusted writer; use the arrow validation APIs to validate an untrusted file's structure. Issues due to malformed files, and well-formed files that contain unexpected or adversarial data, are bugs rather than vulnerabilities, as explained above.
Serialized plans, such as Substrait and datafusion-proto, are treated
as trusted input. If received from an untrusted source, they should be
validated before being passed to DataFusion for execution.
Code that uses DataFusion's public extension APIs (e.g. user defined functions,
TableProvider, ExecutionPlan) is trusted to uphold their contracts (for
example, that any ArrayRef is a valid Arrow array). Issues arising from
violating the API contracts are not considered a DataFusion vulnerability.
We treat all bugs seriously and welcome help fixing them. If you find a bug that does not meet the criteria for a security vulnerability, please report it in the public issue tracker.
For security vulnerabilities do not file a public issue. Follow the ASF security reporting process by emailing security@apache.org.
Include in your report:
- A clear description and minimal reproducer.
- Affected crates and versions.
- Potential impact.