Medium severity4.9NVD Advisory· Published Apr 11, 2025· Updated Jun 17, 2026
CVE-2025-1386
CVE-2025-1386
Description
When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such data to smuggle another query packet into the connection stream.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/ClickHouse/ch-goGo | < 0.65.0 | 0.65.0 |
Affected products
10- ch-go/ch-gov5Range: 0
- ghsa-coords8 versionspkg:golang/github.com/clickhouse/ch-gopkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Tumbleweedpkg:apk/chainguard/teleportpkg:apk/wolfi/telegraf-1.33pkg:apk/wolfi/teleportpkg:apk/chainguard/telegraf-1.34pkg:apk/wolfi/telegraf-1.34pkg:apk/chainguard/telegraf-1.33
< 0.65.0+ 7 more
- (no CPE)range: < 0.65.0
- (no CPE)range: < 0.0.20250422T181640-1.1
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 1.34.2-r0
- (no CPE)range: < 1.34.2-r0
- (no CPE)range: < 0
Patches
Vulnerability mechanics
References
5- github.com/ClickHouse/ch-go/security/advisories/GHSA-m454-3xv7-qj85nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-m454-3xv7-qj85ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-1386ghsaADVISORY
- github.com/ClickHouse/ch-go/commit/0e835663df32b09b828528c07a5507686e6d975eghsaWEB
- pkg.go.dev/vuln/GO-2025-3603ghsaWEB
News mentions
0No linked articles in our index yet.