CVE-2025-1386Medium▾ SunlitCVE-2025-1386- Query smuggling in ch-go library
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
0.4% → 0.4%
When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such data to smuggle another query packet into the connection stream.
If you are using ch-go library, we recommend you to update to at least version 0.65.0.
This issue was found by lixts and reported through our bugcrowd program.
github.com/ClickHouse/ch-go < 0.65.0Upgrade to a patched release:
github.com/ClickHouse/ch-go 0.65.0Connected by shared product, vendor, weakness, or advisory.