Bloomberg's vulnerability profile centers on a narrow set of infrastructure and development tools, including the distributed database system comdb2 and the memory profiling tool memray, which have modest but focused deployment within specialized technical environments. The recurring weakness classes—NULL pointer dereferences, reachable assertions, and cross-site scripting in web interfaces—reflect the memory-safety and input-handling demands typical of systems software and developer tooling. Current severity, exploitation status, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bloomberg over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32722MEDIUM Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Becau | Mar 18, 2026 | 6.1 | 21 | NO | NO |
CVE-2025-46354HIGH A denial of service vulnerability exists in the Distributed Transaction Commit/Abort Operation functionality of Bloomberg Comdb2 8.1. A specially crafted network packet can lead to | Jul 22, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-35966HIGH A null pointer dereference vulnerability exists in the CDB2SQLQUERY protocol buffer message handling of Bloomberg Comdb2 8.1. A specially crafted protocol buffer message can lead t | Jul 22, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-48498HIGH A null pointer dereference vulnerability exists in the Distributed Transaction component of Bloomberg Comdb2 8.1 when processing a number of fields used for coordination. A special | Jul 22, 2025 | 7.5 | 20 | NO | NO |
CVE-2025-36520HIGH A null pointer dereference vulnerability exists in the net_connectmsg Protocol Buffer Message functionality of Bloomberg Comdb2 8.1. A specially crafted network packets can lead to | Jul 22, 2025 | 7.5 | 20 | NO | NO |
CVE-2025-36512HIGH A denial of service vulnerability exists in the Bloomberg Comdb2 8.1 database when handling a distributed transaction heartbeat. A specially crafted protocol buffer message can lea | Jul 22, 2025 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bloomberg.
Media articles that mention a CVE ID that affects a product developed by Bloomberg — matched by CVE ID, not by vendor name.