CVE-2025-6536 is a problematic vulnerability in Tarantool versions up to 3.3.1, specifically within the tm_to_datetime function in src/lib/core/datetime.c. This flaw allows for a reachable assertion, leading to a denial of service. The vulnerability has a low CVSS score of 3.3, requiring local access and low privileges to exploit, with no impact on confidentiality or integrity. While the exploit has been publicly disclosed, there is currently no evidence of active exploitation, nor are there any Metasploit, Nuclei, or ExploitDB modules available. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | Tarantool | 3.3.0, 3.3.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.