{"id":"CVE-2024-37820","aliases":["GHSA-9g6g-xqv5-8g5w","GO-2024-3284"],"title":"PingCAP TiDB nil pointer dereference","summary":"PingCAP TiDB nil pointer dereference","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","vendor":"pingcap","product":"github.com/pingcap/tidb","ecosystem":"go","affected":["github.com/pingcap/tidb < 8.2.0"],"patched":["github.com/pingcap/tidb 8.2.0"],"published":"2024-06-25","updated":"2026-07-15","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-9g6g-xqv5-8g5w","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-37820"},{"url":"https://github.com/pingcap/tidb/issues/53580"},{"url":"https://github.com/pingcap/tidb/commit/3d68bd21240c610c6307713e2bd54a5e71c32608"},{"url":"https://gist.github.com/ycybfhb/a9c1e14ce281f2f553adca84d384b761"},{"url":"https://github.com/advisories/GHSA-9g6g-xqv5-8g5w"},{"url":"https://github.com/pingcap/tidb"}],"tags":["osv","go"],"epss":0.00377,"epssPercentile":0.31586,"ingestedAt":"2026-07-16T18:59:42.523Z","slug":"CVE-2024-37820","body":"## Overview\n\nA nil pointer dereference in PingCAP TiDB v8.2.0-alpha-216-gfe5858b allows attackers to crash the application via expression.inferCollation.\n\n## Affected packages\n\n- `github.com/pingcap/tidb < 8.2.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/pingcap/tidb 8.2.0`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}