CVE-2025-1386- Query smuggling in ch-go library
Description
Published by the National Vulnerability Database
Apr 11, 2025
Published to the GitHub Advisory Database
Apr 12, 2025
Reviewed
Apr 12, 2025
Impact
When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such data to smuggle another query packet into the connection stream.
Patches
If you are using ch-go library, we recommend you to update to at least version 0.65.0.
Credit
This issue was found by lixts and reported through our bugcrowd program.
References