CVE-2025-8865 Information

Description

The YugabyteDB tablet server contains a flaw in its YCQL query handling that can trigger a null pointer dereference when processing certain malformed inputs. An authenticated attacker could exploit this issue to crash the YCQL tablet server resulting in a denial of service.

Reference

https://docs.yugabyte.com/preview/secure/vulnerability-disclosure-policy/

CNNVD-202508-888 (Published: 2025-08-11)

Share on: