ClickHouse, Inc.
First CVE: Aug 1, 2024Active for: 2 years
3
CVEs Published
More CVEs Published than 9% of tracked CNAs
1.5
Avg CVEs / Year
More Avg CVEs / Year than 8% of tracked CNAs
6.8
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by ClickHouse, Inc. as a CNA, 66.7% affect products that ClickHouse, Inc. develops as a vendor.
66.7%
33.3%
Self-reported: 2Third-party: 1
Of all the CVEs published that affect products developed by ClickHouse, Inc., 7.7% are self-published by ClickHouse, Inc. as a CNA.
92.3%
Self-published: 2Published by other CNAs: 24
Trends Over Time
The number and severity of CVEs published by ClickHouse, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 2024
23 months ago
Most Recent CVE
Apr 11, 2025
469 days ago
Top CVEs
All CVEs published by ClickHouse, Inc. as a CNA, regardless of affected vendor or product.
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6873HIGH It is possible to crash or redirect the execution flow of the ClickHouse server process from an unauthenticated vector by sending a specially crafted request to the ClickHouse serv | Aug 1, 2024 | 8.1 | 24 | NO | NO |
CVE-2025-1385HIGH When the library bridge feature is enabled, the clickhouse-library-bridge exposes an HTTP API on localhost. This allows clickhouse-server to dynamically load a library from a speci | Mar 20, 2025 | 7.5 | 20 | NO | NO |
CVE-2025-1386MEDIUM When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such da | Apr 11, 2025 | 4.9 | 16 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA3 CVEs
33%
67%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network3 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (33.3%)
High2 (66.7%)
Unknown0 (0.0%)
User Interaction
None3 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High2 (66.7%)
None1 (33.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (3 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by ClickHouse, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by ClickHouse, Inc. as a CNA — matched by CVE ID, not by organization name.