{"id":"CVE-2026-24825","summary":"a memory leak in ydb-platform/ydb with use of yajl_tree_parse function from src/yail module, which will cause out-of-memory in server and cause crash.","details":"Missing Release of Memory after Effective Lifetime vulnerability in ydb-platform ydb (contrib/libs/yajl modules). This vulnerability is associated with program files yail_tree.C.\n\nThis issue affects ydb: through 24.4.4.2.","modified":"2026-08-12T15:32:12.364962Z","published":"2026-01-27T09:02:51.165Z","database_specific":{"cna_assigner":"GovTech CSG","cwe_ids":["CWE-401"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24825.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24825.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24825"},{"type":"FIX","url":"https://github.com/ydb-platform/ydb/pull/17570"},{"type":"PACKAGE","url":"https://github.com/ydb-platform/ydb"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ydb-platform/ydb","events":[{"introduced":"0"},{"fixed":"fd1e65b06629d970ecd292e285fc34861850c950"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"24.4.4.2"},{"fixed":"24.4.4.2"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["24.4.4.1","24.4.4","24.4.3","24.4.2","24.4.1","24.3.15","24.3.14","24.3.13","24.3.12","24.3.11","24.3.10","24.3.9","24.3.8","24.3.7","24.3.6","24.3.5","24.3.4","24.3.3","CLI_2.10.0","CLI_2.9.0","24.1.1","CLI_2.8.0","CLI_2.7.0","CLI_2.6.0","CLI_2.5.0","CLI_2.4.0","CLI_2.3.0","CLI_2.2.0","CLI_2.1.1","CLI_2.1.0","CLI_2.0.1"],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"256885210891556907294139742507356392503","length":17318},"id":"CVE-2026-24825-233edc51","signature_type":"Function","signature_version":"v1","source":"https://github.com/ydb-platform/ydb/commit/fd1e65b06629d970ecd292e285fc34861850c950","target":{"file":"ydb/core/tx/schemeshard/ut_serverless/ut_serverless.cpp","function":"Y_UNIT_TEST_SUITE"}},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["282070622794628338862662018262788621167","54001086052477901182489184683665166319","257332189130196016759469850708140204346","145704891226431392480406423188573520979","18447838550463146205102328877733643836","290349102357548503959051733913057911292"]},"id":"CVE-2026-24825-56631a3c","signature_type":"Line","signature_version":"v1","source":"https://github.com/ydb-platform/ydb/commit/fd1e65b06629d970ecd292e285fc34861850c950","target":{"file":"ydb/core/tx/schemeshard/ut_serverless/ut_serverless.cpp"}},{"signature_version":"v1","source":"https://github.com/ydb-platform/ydb/commit/fd1e65b06629d970ecd292e285fc34861850c950","target":{"file":"ydb/core/tx/schemeshard/schemeshard__serverless_storage_billing.cpp"},"deprecated":false,"digest":{"line_hashes":["195208270104957154282838463576636372641","175746043977049791637544528929522263433","167781020423047215083720944060776781390"],"threshold":0.9},"id":"CVE-2026-24825-bc90cf73","signature_type":"Line"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24825.json","vanir_signatures_modified":"2026-08-12T15:32:12Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/S:N/AU:Y/R:U/V:D/RE:L/U:Amber"}]}