clickhouse has 2 CVEs on record between 2024 and 2025. The median CVSS is 8.8 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.8
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Weakness classes
Products
- github.com/ClickHouse/ch-go 1
- java_libraries 1
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2024-23689High· 8.8Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificat…49CVE-2025-1386MediumCVE-2025-1386- Query smuggling in ch-go library28
clickhouse vulnerabilities
CVEs affecting clickhouse, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2025-1386MediumCVE-2025-1386- Query smuggling in ch-go library
CVE-2025-1386- Query smuggling in ch-go library
▾ SunlitClickHouse · github.com/ClickHouse/ch-goEPSS 0.38%via OSV
CVE-2024-23689High· 8.8Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificat…
Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificat…
▾ Twilightclickhouse · java_librariesEPSS 0.68%via NVD