GHSA-28xx-pppm-vqff
### Impact Transactions were NOT committed despite the explicit `options.WithCommit` flag using table service client. Because of this, clients did not commit changes to the transaction, relying on the fact that the transaction commit was successful. This led (in rare cases) to a loss of data consistency. ### Patches `ydb-go-sdk` contains this problem in versions from [v3.104.6](https://github.com/ydb-platform/ydb-go-sdk/releases/tag/v3.104.6) to [v3.134.1](https://github.com/ydb-platform/ydb-go-sdk/releases/tag/v3.134.1). The fix for this problem has been released in version [v3.134.2](https://github.com/ydb-platform/ydb-go-sdk/releases/tag/v3.134.2) (https://github.com/ydb-platform/ydb-go-sdk/pull/2091). ### Workarounds 1) Use explicit `table.Transaction.CommitTx(ctx)` instead use `options.WithCommit()`. 2) Use transaction retrier `db.Table().DoTx(ctx, lambda)` instead explicit start transaction on session. 3) Use query client `db.Query().Do(ctx, lambda)` with the same logic in `lambda` ### Resources Commit with bug https://github.com/ydb-platform/ydb-go-sdk/commit/251128a64763555d9a79ee7a131dd154c9000eb9 Commit with fix https://github.com/ydb-platform/ydb-go-sdk/commit/25dcff4c41153f1f9413512ba12999b40bf7154d
Properties
- ghsa_id
- GHSA-28xx-pppm-vqff
- severity
- low
- summary
- ydb-go-sdk's transactions are not committed using the `options.WithCommit()` option on last call `table.Transaction.Execute` in transaction
- cve_id
- GHSA-28xx-pppm-vqff
- is_ghsa_only
- true
- ghsa_published
- 2026-04-30T18:21:04Z
- source_url
- https://github.com/advisories/GHSA-28xx-pppm-vqff
- ghsa_updated
- 2026-04-30T18:21:05Z
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph