CVE-2025-1386

Published
View on NVD ↗
CVSS v3
4.9
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such data to smuggle another query packet into the connection stream.

Low-level Go Client for ClickHouse
GitHubGitHub
424