CVE-2025-8862: Yugabytedb Inc Yugabytedb

High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.

YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag configurations. To mitigate this, we recommend upgrading the database to a version where this information is properly redacted.

Affected products

  • Yugabytedb Inc Yugabytedb: from 2024.1.0, before 2024.1.3 (fixed in 2024.1.3); from 2.20.0.0, before 2.20.7.0 (fixed in 2.20.7.0); from 2.23.0.0, before 2.23.1.0 (fixed in 2.23.1.0)

Published 2025-08-11. Last modified 2026-06-17.