VYPR

Clickhouse

by Clickhouse

Source repositories

CVEs (26)

  • CVE-2018-14672MedAug 15, 2019
    risk 0.28cvss 5.3epss 0.02

    In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages.

  • CVE-2026-51992Jul 29, 2026
    risk 0.00cvss epss 0.01

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. ClickHouse's PostgreSQL integration intentionally allows users with valid PostgreSQL credentials to execute queries against a remote PostgreSQL server. No vulnerability in ClickHouse is…

  • CVE-2024-22412LowMar 18, 2024
    risk 0.00cvss 2.4epss 0.01

    ClickHouse is an open-source column-oriented database management system. A bug exists in the cloud ClickHouse offering prior to version 24.0.2.54535 and in github.com/clickhouse/clickhouse version 23.1. Query caching bypasses the role based access controls and the policies being…

  • CVE-2023-48704HigDec 22, 2023
    risk 0.00cvss 7.0epss 0.01

    ClickHouse is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially crafted payload to the native interface…

  • CVE-2023-48298MedDec 21, 2023
    risk 0.00cvss 5.9epss 0.01

    ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. This vulnerability is an integer underflow resulting in crash due to stack buffer overflow in decompression of FPC codec. It can be triggered…

  • CVE-2019-18657MedOct 31, 2019
    risk 0.00cvss 5.3epss 0.01

    ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function.

Page 2 of 2