Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-24148 | The YugabyteDB tablet server contains a flaw in its YCQL query handling that can trigger a null pointer dereference when processing certain malformed inputs. An authenticated attacker could exploit this issue to crash the YCQL tablet server, resulting in a denial of service. |
Tue, 12 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yugabyte
Yugabyte yugabytedb |
|
| Vendors & Products |
Yugabyte
Yugabyte yugabytedb |
Tue, 12 Aug 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | yugabytedb: YugabyteDB null pointer dereference | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Mon, 11 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 11 Aug 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The YugabyteDB tablet server contains a flaw in its YCQL query handling that can trigger a null pointer dereference when processing certain malformed inputs. An authenticated attacker could exploit this issue to crash the YCQL tablet server, resulting in a denial of service. | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Yugabyte
Published:
Updated: 2025-08-11T15:04:04.232Z
Reserved: 2025-08-11T13:30:55.802Z
Link: CVE-2025-8865
Updated: 2025-08-11T15:02:56.012Z
Status : Deferred
Published: 2025-08-11T15:15:29.203
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-8865
OpenCVE Enrichment
Updated: 2025-08-12T11:47:03Z
EUVD