CVE-2025-8865: Yugabytedb Inc Yugabytedb

Medium severity, CVSS 4.1. EPSS: 0.2% chance of exploitation in the next 30 days.

The YugabyteDB tablet server contains a flaw in its YCQL query handling that can trigger a null pointer dereference when processing certain malformed inputs. An authenticated attacker could exploit this issue to crash the YCQL tablet server, resulting in a denial of service.

Affected products

  • Yugabytedb Inc Yugabytedb: from 2024.1.0.0, before 2024.1.3.0 (fixed in 2024.1.3.0); from 2024.2.0.0, before 2024.2.2.5 (fixed in 2024.2.2.5); from 2.20.0.0, before 2.20.9.0 (fixed in 2.20.9.0)

Published 2025-08-11. Last modified 2026-06-17.