Yugabyte, Inc. develops a distributed SQL database platform spanning its core YugabyteDB product and managed cloud variants, positioning itself as a supply-chain dependency for stateful infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and cluster around memory-safety and access-control weaknesses—buffer overflows, exposure of sensitive state, and improper authorization—that are characteristic of systems managing large datasets and cluster state. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yugabyte, Inc. over time
Of all the CVEs published by Yugabyte, Inc. as a CNA, 38.9% affect products that Yugabyte, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Yugabyte, Inc., 77.8% are self-published by Yugabyte, Inc. as a CNA.
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0745CRITICAL
The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary
files through the backup upload endpoint by using path trave | Feb 9, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-37397CRITICAL An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is en | Aug 12, 2022 | 9.8 | 30 | NO | NO |
CVE-2023-0574CRITICAL Server-Side Request Forgery (SSRF), Improperly Controlled Modification of Dynamically-Determined Object Attributes, Improper Restriction of Excessive Authentication Attempts vulner | Feb 9, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-0575CRITICAL External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (Devops | Feb 9, 2023 | 9.8 | 27 | NO | NO |
CVE-2019-3800HIGH CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local | Aug 5, 2019 | 7.8 | 26 | NO | NO |
CVE-2024-41435HIGH YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter. | Sep 3, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-6001HIGH Prometheus metrics are available without
authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment. | Nov 8, 2023 | 7.5 | 21 | NO | NO |
CVE-2023-4640HIGH The controller responsible for setting the logging level does not include any authorization
checks to ensure the user is authenticated. This can be seen by noting that it extends
C | Aug 30, 2023 | 7.5 | 21 | NO | NO |
CVE-2023-6002MEDIUM YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files can allow an unprivileged attacker to forge log entries or inj | Nov 8, 2023 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yugabyte, Inc..
Media articles that mention a CVE ID that affects a product developed by Yugabyte, Inc. — matched by CVE ID, not by vendor name.