FlawAtlas
Search the atlas
CVE-2025-1386 Moderate

Query smuggling in ch-go library

When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such data to smuggle another query packet into the connection stream.

Exploit probability 0.4%
Published April 11, 2025
Required by Not available
Last source change August 13, 2026

02 / AFFECTED SOFTWARE

Affected packages

Go github.com/ClickHouse/ch-go
Go github.com/ClickHouse/ch-go
Unknown Unknown

102 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GO-2025-3603

Query smuggling in ch-go library in github.com/ClickHouse/ch-go

View original source
Open Source Vulnerabilities CVE-2025-1386

When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such data to smuggle another query packet into the connection stream.

View original source
Open Source Vulnerabilities GHSA-m454-3xv7-qj85

### Impact When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such data to smuggle another query packet into the connection stream. ### Patches If you are using ch-go library, we recommend you to update to at least version 0.65.0. ### Credit This issue was found by lixts and reported through our bugcrowd program.

View original source

05 / REFERENCES

Further evidence