Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-10732 | CVE-2025-1386- Query smuggling in ch-go library |
Github GHSA |
GHSA-m454-3xv7-qj85 | CVE-2025-1386- Query smuggling in ch-go library |
Fri, 19 Dec 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Clickhouse
Clickhouse ch |
|
| CPEs | cpe:2.3:a:clickhouse:ch:*:*:*:*:*:go:*:* | |
| Vendors & Products |
Clickhouse
Clickhouse ch |
|
| Metrics |
cvssV3_1
|
Fri, 11 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-444 | |
| Metrics |
ssvc
|
Fri, 11 Apr 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such data to smuggle another query packet into the connection stream. | |
| Title | Query smuggling in ch-go library | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ClickHouse
Published:
Updated: 2025-04-11T16:01:28.660Z
Reserved: 2025-02-17T02:21:07.315Z
Link: CVE-2025-1386
Updated: 2025-04-11T15:09:36.694Z
Status : Analyzed
Published: 2025-04-11T05:15:29.583
Modified: 2025-12-19T18:47:13.043
Link: CVE-2025-1386
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA