VYPR

Starrocks

by StarRocks

CVEs (3)

  • CVE-2026-80346HigAug 26, 2026
    risk 0.39cvss 7.1epss 0.00

    StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. Every other statement type routed through AuthorizerStmtVisitor calls into Authorizer before execution, but visitDropMaterializedViewStatement returns immediately with a comment stating…

  • CVE-2026-82306MedAug 28, 2026
    risk 0.35cvss 6.5epss 0.00

    StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfiltered query history for all users. Authenticated attackers with low privileges can access full SQL text, execution plans, and profiling data from every query…

  • CVE-2026-82276MedAug 28, 2026
    risk 0.27cvss 5.3epss 0.00

    StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override execute() directly instead of implementing executeWithoutPassword(). Attackers can access six unauthenticated endpoints on the frontend HTTP port to disclose…