Aerospike operates a focused in-memory database platform and client libraries that serve high-throughput caching and real-time data workloads, placing it among more prominent vendors in the distributed systems landscape despite a narrow product footprint. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the memory-safety and data-access demands of a performance-oriented database engine; recurrent exposure centers on out-of-bounds writes, deserialization flaws, OS command injection, and array-indexing weaknesses. Defenders should prioritize patching this vendor's releases, particularly where Aerospike instances are accessible from untrusted networks; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aerospike over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13151CRITICAL Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query. It attempts t | Aug 5, 2020 | 9.8 | 89 | NO | YES |
CVE-2016-9053CRITICAL An exploitable out-of-bounds indexing vulnerability exists within the RW fabric message particle type of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause th | Feb 21, 2017 | 9.8 | 35 | NO | NO |
CVE-2016-9051CRITICAL An exploitable out-of-bounds write vulnerability exists in the batch transaction field parsing functionality of Aerospike Database Server 3.10.0.3. A specially crafted packet can c | Feb 21, 2017 | 9.8 | 34 | NO | NO |
CVE-2023-36480CRITICAL The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike server. Prior to versions 7.0.0, 6.2.0, 5.2.0, and 4.5.0 some of | Aug 4, 2023 | 9.8 | 28 | NO | NO |
CVE-2016-9054CRITICAL An exploitable stack-based buffer overflow vulnerability exists in the querying functionality of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause a stack-ba | Jan 26, 2017 | 9.8 | 27 | NO | NO |
CVE-2016-9052CRITICAL An exploitable stack-based buffer overflow vulnerability exists in the querying functionality of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause a stack-ba | Jan 26, 2017 | 9.8 | 27 | NO | NO |
CVE-2016-9050HIGH An exploitable out-of-bounds read vulnerability exists in the client message-parsing functionality of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause an ou | Jan 26, 2017 | 8.2 | 25 | NO | NO |
CVE-2016-10558HIGH aerospike is an Aerospike add-on module for Node.js. aerospike versions below 2.4.2 download binary resources over HTTP, which leaves the module vulnerable to MITM attacks. It may | May 29, 2018 | 8.1 | 23 | NO | NO |
CVE-2016-9049HIGH An exploitable denial-of-service vulnerability exists in the fabric-worker component of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause the server process | Feb 21, 2017 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aerospike.
Media articles that mention a CVE ID that affects a product developed by Aerospike — matched by CVE ID, not by vendor name.