CVE-2025-1386- Query smuggling in ch-go library
Description
Published by the National Vulnerability Database
Apr 11, 2025
Published to the GitHub Advisory Database
Apr 12, 2025
Reviewed
Apr 12, 2025
Last updated
Apr 23, 2025
Impact
When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such data to smuggle another query packet into the connection stream.
Patches
If you are using ch-go library, we recommend you to update to at least version 0.65.0.
Credit
This issue was found by lixts and reported through our bugcrowd program.
References