DuckDB is an in-process analytical SQL database engine whose modest vulnerability footprint reflects its narrowly scoped, embedded role in data processing and analytics applications. Observed weakness classes center on information exposure, cryptographic implementation gaps, and incomplete vulnerability data, consistent with the handling of structured data and credential management in database systems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Duckdb over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-41672HIGH DuckDB is a SQL database management system. In versions 1.0.0 and prior, content in filesystem is accessible for reading using `sniff_csv`, even with `enable_external_access=false` | Jul 24, 2024 | 7.5 | 22 | NO | NO |
CVE-2025-64429MEDIUM DuckDB is a SQL database management system. DuckDB implemented block-based encryption of DB on the filesystem starting with DuckDB 1.4.0. There are a few issues related to this imp | Nov 12, 2025 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Duckdb.
Media articles that mention a CVE ID that affects a product developed by Duckdb — matched by CVE ID, not by vendor name.