Clickhouse
by Clickhouse
Source repositories
CVEs (26)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-14672 | Med | 0.28 | 5.3 | 0.02 | Aug 15, 2019 | In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages. | ||
| CVE-2026-51992 | 0.00 | — | 0.01 | Jul 29, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. ClickHouse's PostgreSQL integration intentionally allows users with valid PostgreSQL credentials to execute queries against a remote PostgreSQL server. No vulnerability in ClickHouse is… | |||
| CVE-2024-22412 | Low | 0.00 | 2.4 | 0.01 | Mar 18, 2024 | ClickHouse is an open-source column-oriented database management system. A bug exists in the cloud ClickHouse offering prior to version 24.0.2.54535 and in github.com/clickhouse/clickhouse version 23.1. Query caching bypasses the role based access controls and the policies being… | ||
| CVE-2023-48704 | Hig | 0.00 | 7.0 | 0.01 | Dec 22, 2023 | ClickHouse is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially crafted payload to the native interface… | ||
| CVE-2023-48298 | Med | 0.00 | 5.9 | 0.01 | Dec 21, 2023 | ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. This vulnerability is an integer underflow resulting in crash due to stack buffer overflow in decompression of FPC codec. It can be triggered… | ||
| CVE-2019-18657 | Med | 0.00 | 5.3 | 0.01 | Oct 31, 2019 | ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function. |
- risk 0.28cvss 5.3epss 0.02
In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages.
- CVE-2026-51992Jul 29, 2026risk 0.00cvss —epss 0.01
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. ClickHouse's PostgreSQL integration intentionally allows users with valid PostgreSQL credentials to execute queries against a remote PostgreSQL server. No vulnerability in ClickHouse is…
- risk 0.00cvss 2.4epss 0.01
ClickHouse is an open-source column-oriented database management system. A bug exists in the cloud ClickHouse offering prior to version 24.0.2.54535 and in github.com/clickhouse/clickhouse version 23.1. Query caching bypasses the role based access controls and the policies being…
- risk 0.00cvss 7.0epss 0.01
ClickHouse is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially crafted payload to the native interface…
- risk 0.00cvss 5.9epss 0.01
ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. This vulnerability is an integer underflow resulting in crash due to stack buffer overflow in decompression of FPC codec. It can be triggered…
- risk 0.00cvss 5.3epss 0.01
ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function.
Page 2 of 2