Missing Release of Memory after Effective Lifetime vulnerability in ydb-platform ydb (contrib/libs/yajl modules). This vulnerability is associated with program files yail_tree.C.

This issue affects ydb: through 24.4.4.2.

Project Subscriptions

Vendors Products
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 02 Feb 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

threat_severity

Moderate


Tue, 27 Jan 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Ydb
Ydb ydb
Vendors & Products Ydb
Ydb ydb

Tue, 27 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 27 Jan 2026 09:15:00 +0000

Type Values Removed Values Added
Description Missing Release of Memory after Effective Lifetime vulnerability in ydb-platform ydb (contrib/libs/yajl modules). This vulnerability is associated with program files yail_tree.C. This issue affects ydb: through 24.4.4.2.
Title a memory leak in ydb-platform/ydb with use of yajl_tree_parse function from src/yail module, which will cause out-of-memory in server and cause crash.
Weaknesses CWE-401
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/S:N/AU:Y/R:U/V:D/RE:L/U:Amber'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GovTech CSG

Published:

Updated: 2026-01-27T16:57:43.248Z

Reserved: 2026-01-27T08:59:05.366Z

Link: CVE-2026-24825

cve-icon Vulnrichment

Updated: 2026-01-27T16:57:39.717Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-27T09:15:53.347

Modified: 2026-01-27T14:59:34.073

Link: CVE-2026-24825

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-01-27T09:02:51Z

Links: CVE-2026-24825 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-01-27T20:16:50Z

Weaknesses