CVE-2025-8862: High severity Yugabyte YugabyteDB vulnerability
YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag configurations. To mitigate this, we recommend upgrading the database to a version where this information is properly redacted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8862?
CVE-2025-8862 is considered to have a moderate severity due to exposure of potentially sensitive configuration information.
How do I fix CVE-2025-8862?
To fix CVE-2025-8862, it is recommended to upgrade to a version of YugabyteDB where sensitive gflag configurations are properly redacted.
What information is at risk in CVE-2025-8862?
CVE-2025-8862 may expose sensitive gflag configurations that could lead to unauthorized access or exploitation.
Is there a workaround for CVE-2025-8862?
Currently, the primary mitigation for CVE-2025-8862 is to upgrade to a secure version of YugabyteDB, as there are no definitive workarounds.
Who is affected by CVE-2025-8862?
All users of YugabyteDB that have diagnostics information enabled may be affected by CVE-2025-8862.