Back to search
CVE-2025-8865
Published: Aug 11, 2025
Modified: Aug 11, 2025
PUBLISHED
Description
The YugabyteDB tablet server contains a flaw in its YCQL query handling that can trigger a null pointer dereference when processing certain malformed inputs. An authenticated attacker could exploit this issue to crash the YCQL tablet server, resulting in a denial of service.
| Vendor | Product | Versions |
|---|---|---|
YugabyteDB Inc | YugabyteDB | affected 2024.1.0.0 - < 2024.1.3.0affected 2024.2.0.0 - < 2024.2.2.5affected 2.20.0.0 - < 2.20.9.0 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now