Intel

AIKIDO-2025-10067

github.com/ydb-platform/ydb-go-sdk/v3 is vulnerable to NULL Pointer Dereference

NULL Pointer Dereference Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

16

Low Risk

This Affects:

GOgithub.com/ydb-platform/ydb-go-sdk/v3
3.34.0 - 3.99.1
Fixed in 3.99.2

TL;DR

Affected versions of this package are vulnerable to an explicit null-dereference in the internal/credentials/static.go::parseExpiresAt function. This flaw can lead to crashes, potentially causing a Denial of Service (DoS). Proper handling of null values is necessary to prevent such issues, as it could result in system instability or unresponsiveness when exploited.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/ydb-platform/ydb-go-sdk/v3 is vulnerable to NULL Pointer Dereference in versions 3.34.0 - 3.99.1.

How to fix this

Upgrade the github.com/ydb-platform/ydb-go-sdk/v3 library to the patch version.