PingCAP develops TiDB, a distributed SQL database platform that is gaining traction in mission-critical deployments despite a narrow product footprint. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through weakness classes including buffer overflows, NULL-pointer dereferences, improper authentication, resource-consumption flaws, and format-string issues that are characteristic of systems-level database implementations. Defenders should prioritize patches for this vendor given the severity profile and the elevated risk posed by database-tier exposure; live exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by PingCAP (US), Inc. over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3023CRITICAL Use of Externally-Controlled Format String in GitHub repository pingcap/tidb prior to 6.4.0, 6.1.3. | Nov 4, 2022 | 9.8 | 30 | NO | NO |
CVE-2024-41433CRITICAL PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Service | Sep 3, 2024 | 9.8 | 27 | NO | NO |
CVE-2022-31011HIGH TiDB is an open-source NewSQL database that supports Hybrid Transactional and Analytical Processing (HTAP) workloads. Under certain conditions, an attacker can construct malicious | May 31, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-34969HIGH PingCAP TiDB v6.1.0 was discovered to contain a NULL pointer dereference. | Aug 3, 2022 | 7.5 | 24 | NO | NO |
CVE-2024-35618HIGH PingCAP TiDB v7.5.1 was discovered to contain a NULL pointer dereference via the component SortedRowContainer. | May 24, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-33809MEDIUM PingCAP TiDB v7.5.1 was discovered to contain a buffer overflow vulnerability, which could lead to database crashes and denial of service attacks. | May 24, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-41434MEDIUM PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via a crafted input | Sep 3, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by PingCAP (US), Inc..
Media articles that mention a CVE ID that affects a product developed by PingCAP (US), Inc. — matched by CVE ID, not by vendor name.