YugabyteDB Tablet Server YCQL Null Pointer Dereference Vulnerability Leading to Denial-of-Service

Vulnerability

A null pointer dereference vulnerability has been identified in the YugabyteDB tablet server's YCQL query handling. This flaw can be triggered by certain malformed inputs, allowing an authenticated attacker to crash the YCQL tablet server and cause a denial-of-service condition.

Impact

Exploitation of this vulnerability leads to a crash of the YCQL tablet server, causing a denial-of-service condition.

Added: Aug 11, 2025, 3:17 PM
Updated: Aug 11, 2025, 3:17 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
2.5
exploitability
4.9
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.