Intel

AIKIDO-2025-10072

github.com/ydb-platform/ydb-go-sdk/v3 is vulnerable to Infinite Loop

Infinite Loop Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

16

Low Risk

This Affects:

GOgithub.com/ydb-platform/ydb-go-sdk/v3
3.26.0 - 3.99.2
Fixed in 3.99.3

TL;DR

Affected versions of this package are vulnerable to an infinite loop in the internal/balancer/local_dc.go::getRandomEndpoints function. This flaw can cause the system to hang indefinitely, leading to a Denial of Service (DoS) by consuming resources and rendering the application unresponsive.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/ydb-platform/ydb-go-sdk/v3 is vulnerable to Infinite Loop in versions 3.26.0 - 3.99.2.

How to fix this

Upgrade the github.com/ydb-platform/ydb-go-sdk/v3 library to the patch version.