Ydb is a distributed database platform with a narrow but strategically deployed footprint, and its vulnerability profile centers on the core database engine and its Go client SDK. The observed weakness classes—sensitive information leakage into log files and out-of-bounds reads—reflect the data-handling and memory-access complexity inherent to database systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ydb over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28228CRITICAL Out-of-bounds read was discovered in YDB server. An attacker could construct a query with insert statement that would allow him to read sensitive information from other memory loca | Dec 23, 2022 | 9.1 | 28 | NO | NO |
CVE-2023-45825MEDIUM ydb-go-sdk is a pure Go native and database/sql driver for the YDB platform. Since ydb-go-sdk v3.48.6 if you use a custom credentials object (implementation of interface Credential | Oct 19, 2023 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ydb.
Media articles that mention a CVE ID that affects a product developed by Ydb — matched by CVE ID, not by vendor name.