When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such data to smuggle another query packet into the connection stream.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-444 | |
Metrics |
ssvc
|
Fri, 11 Apr 2025 04:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such data to smuggle another query packet into the connection stream. | |
Title | Query smuggling in ch-go library | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: ClickHouse
Published: 2025-04-11T04:27:35.846Z
Updated: 2025-04-11T16:01:28.660Z
Reserved: 2025-02-17T02:21:07.315Z
Link: CVE-2025-1386

Updated: 2025-04-11T15:09:36.694Z

Status : Awaiting Analysis
Published: 2025-04-11T05:15:29.583
Modified: 2025-04-11T16:15:19.490
Link: CVE-2025-1386

No data.