CVE-2025-1386

MEDIUM

Clickhouse CH < 0.65.0 - HTTP Request Smuggling

Title source: rule
STIX 2.1

Description

When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such data to smuggle another query packet into the connection stream.

Scores

CVSS v3 4.9
EPSS 0.0007
EPSS Percentile 20.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-444
Status published
Products (2)
clickhouse/ch < 0.65.0
ClickHouse/ch-go 0 - 0.65.0Go
Published Apr 11, 2025
Tracked Since Feb 18, 2026