github.com/ydb-platform/ydb-go-sdk/v3 is vulnerable to NULL Pointer Dereference
16
Low Risk
Affected versions of this package are vulnerable to an explicit null-dereference in the internal/credentials/static.go::parseExpiresAt function. This flaw can lead to crashes, potentially causing a Denial of Service (DoS). Proper handling of null values is necessary to prevent such issues, as it could result in system instability or unresponsiveness when exploited.
You are affected if you are using a version that falls within the vulnerable range.
github.com/ydb-platform/ydb-go-sdk/v3 is vulnerable to NULL Pointer Dereference in versions 3.34.0 - 3.99.1.
Upgrade the github.com/ydb-platform/ydb-go-sdk/v3 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant