Back to blog

// OSSeva Blog

Security

ClickHouse Vulnerabilities by Version: CVEs for ClickHouse 22.x to 26.x, LTS and Stable

Matt Reynolds9 min read

The short answer

ClickHouse supports four releases for security updates today: the stable releases 26.9 and 26.7, and the LTS releases 26.8 and 26.3. Every other release is marked unsupported in the project's SECURITY.md, including 26.1, 26.2, 26.4 to 26.6 and all of 25.x, with the 25.3 and 25.8 LTS lines. No CVE has been published against any 26.x release. The newest entry in the ClickHouse security changelog is CVE-2025-1385, a code execution path through the library bridge, fixed in 25.1.5.5 and in four 24.x lines.

A short CVE list is not the same as a safe old release. ClickHouse fixes security issues only on the releases it supports at the time, so every CVE in its changelog was fixed on a handful of lines and on none of the others. The next one will reach only 26.3, 26.7, 26.8, 26.9 or their successors. A cluster on an unsupported release can only pick it up by upgrading.

ClickHouse release lines and their CVEs

Support status is from SECURITY.md on 6 October 2026, LTS release dates from the ClickHouse changelogs and patch releases from the ClickHouse GitHub releases. The production FAQ says the three latest stable releases get bug fix backports and each LTS release is supported for a year after its first release. Each row lists the CVEs from the ClickHouse security changelog that have no fix on the line.

LineUpstream statusLatest releaseCVEs with no fix on this lineUpstream fix on this line
26.9 and 26.7 stableSupported while among the three latest stable releases26.9.11.2 and 26.7.22.4, 5 October 2026None publishedNot applicable
26.8 LTSSupported; released 27 August 2026, for one year26.8.18.2, 5 October 2026None publishedNot applicable
26.3 LTSSupported; released 26 March 2026, for one year26.3.42.3, 5 October 2026None publishedNot applicable
26.1, 26.2, 26.4 to 26.6Unsupported; out of the stable window26.6.8.7, 16 September 2026; 26.5.7.64; 26.4.5.143; 26.2.19.43; 26.1.12.23None publishedNo upstream fix for anything published from now on
25.x, including 25.3 and 25.8 LTSUnsupported25.8.33.6, 26 August 2026; 25.3.14.14, 2 February 2026None published; 25.1 before 25.1.5.5 has CVE-2025-138525.1.5.5 for CVE-2025-1385
24.xUnsupported24.8.14.39 and 24.3.18.7, 19 February 2025CVE-2025-1385 and CVE-2024-6873 on the 24.x lines that had no fix published24.3.18.6, 24.8.14.27, 24.11.5.34 and 24.12.5.65 for CVE-2025-1385; 24.3.4.147, 24.4.2.141, 24.5.1.1763 and 24.6.1.4423 for CVE-2024-6873
23.xUnsupported23.8.16.40 LTSThe 2023 codec CVEs on lines other than 23.3, 23.8, 23.9 and 23.10; CVE-2024-22412 on lines other than 23.3, 23.8 and 23.12; CVE-2024-6873 on 23.8 before 23.8.15.35Fixes published for 23.3, 23.8, 23.9, 23.10 and 23.12 only
22.x and olderUnsupportedVaries by lineCVE-2023-47118, CVE-2023-48298 and CVE-2023-48704; CVE-2022-44010 and CVE-2022-44011 on lines other than 22.3 and 22.6 to 22.922.3.12.19 and 22.6 to 22.9 patches for the 2022 CVEs; nothing for the 2023 codec CVEs

The CVE-2025-1385 record names fixes only for 24.3, 24.8, 24.11, 24.12 and 25.1, the lines ClickHouse supported at the time, and lists nothing else as affected. The CVE-2024-6873 record marks every version outside its five ranges as unknown. Neither names a fix for lines such as 24.1, 24.2, 24.9 or 24.10, so a cluster on one of those should not count on being unaffected. For release dates on every line, see the ClickHouse end-of-life tracker.

Notable ClickHouse CVEs by release line

CVSS is NVD's own score where NVD has scored the record. NVD has deferred CVE-2025-1385 and CVE-2024-6873 and CISA-ADP has added no score, so for those two the score is ClickHouse's own as the CNA. None of these CVEs is in CISA's Known Exploited Vulnerabilities catalogue.

CVEIssueCVSSAffectedFixed in
CVE-2023-47118A crafted payload to the native interface, port 9000 by default, overflows a heap buffer in the T64 codec and crashes the server, with no authentication9.8 (NVD)23.3 before 23.3.16.7; 23.8 before 23.8.6.16; 23.9 before 23.9.4.11; 23.10 before 23.10.2.13; and older23.3.16.7, 23.8.6.16, 23.9.4.11, 23.10.2.13
CVE-2021-43304A malicious query overflows a heap buffer in the LZ4 codec8.8 (NVD)Before 21.10.2.1521.10.2.15
CVE-2021-43305The same LZ4 overflow through a different copy operation8.8 (NVD)Before 21.10.2.1521.10.2.15
CVE-2024-6873A crafted request to the native interface can crash the server or redirect execution within a 256-byte range, with no authentication8.1 (ClickHouse, CVSS 3.1)23.8 before 23.8.15.35; 24.3 before 24.3.4.147; 24.4 before 24.4.2.141; 24.5 before 24.5.1.1763; 24.6 before 24.6.1.442323.8.15.35, 24.3.4.147, 24.4.2.141, 24.5.1.1763, 24.6.1.4423
CVE-2021-42387A malicious query reads past the upper bound of a heap buffer in the LZ4 codec8.1 (NVD)Before 21.10.2.1521.10.2.15
CVE-2021-42388A malicious query reads past the lower bound of a heap buffer in the LZ4 codec8.1 (NVD)Before 21.10.2.1521.10.2.15
CVE-2025-1385With the library bridge enabled, a user who can use both file-upload table engines and the bridge can load a library and run code on the server7.5 (ClickHouse, CVSS 4.0)24.3 before 24.3.18.6; 24.8 before 24.8.14.27; 24.11 before 24.11.5.34; 24.12 before 24.12.5.65; 25.1 before 25.1.5.524.3.18.6, 24.8.14.27, 24.11.5.34, 24.12.5.65, 25.1.5.5
CVE-2023-48298An integer underflow in the FPC codec crashes the server, with no authentication7.5 (NVD)23.3 before 23.3.17.13; 23.8 before 23.8.7.24; 23.9 before 23.9.5.29; 23.10 before 23.10.4.2523.3.17.13, 23.8.7.24, 23.9.5.29, 23.10.4.25
CVE-2023-48704A crafted payload to the native interface overflows a heap buffer in the Gorilla codec, with no authentication7.5 (NVD)23.3 before 23.3.18.15; 23.8 before 23.8.8.20; 23.9 before 23.9.6.20; 23.10 before 23.10.5.2023.3.18.15, 23.8.8.20, 23.9.6.20, 23.10.5.20
CVE-2022-44010A crafted request to the HTTP endpoint, port 8123 by default, overflows a heap buffer and crashes the server, with no authentication7.5 (NVD)Before 22.3.12.19; 22.6 to 22.9 before their fixed patches22.3.12.19, 22.6.6.16, 22.7.4.16, 22.8.2.11, 22.9.1.2603
CVE-2022-44011A user who can load data crashes the server with a malformed CapnProto object6.5 (NVD)The same as CVE-2022-44010The same as CVE-2022-44010
GHSA-8j36-9622-f5cjCRLF injection through the url() table function lets a privileged user send arbitrary HTTP requests to systems the server can reach5.8 (GitHub advisory, CVSS 3.1)Before 23.7.6.11123.7.6.111 and later releases
CVE-2024-22412With the query cache enabled, users who switch roles can get results cached for another role, bypassing role-based access controls4.9 (NVD)23.1 and later before the fixed releases23.3.22.3, 23.8.12.13, 23.12.6.19, 24.1.1.2048

The pattern is the native protocol. The most serious rows are malformed compressed data or requests sent to port 9000 or 8123, and five of them need no credentials at all. The JFrog findings from 2021 also include three divide-by-zero crashes in the Delta, DeltaDouble and Gorilla codecs, CVE-2021-42389 to CVE-2021-42391, fixed in 21.10.2.15 as well. CVE-2025-1385 is different: it needs the library bridge to be configured, which the advisory says can be checked by looking for a library_bridge port in the server configuration, and a user privileged enough to use the file-upload table engines.

A search for ClickHouse on NVD returns many more CVEs than this. Most of them are in other products that store data in ClickHouse, such as SQL injection in the query builders of observability and analytics tools, and are fixed in those products, not in the ClickHouse server. One 2026 CVE filed by ClickHouse itself, CVE-2026-51992, was rejected, because it described intended behaviour of the PostgreSQL integration.

What each line gets

26.3, 26.7, 26.8 and 26.9

These are the supported releases, and they get frequent patch releases; all four had a new one on 5 October 2026. Stable releases drop out as new ones arrive, so 26.7 is expected to leave the window when 26.10 ships. Under the one-year LTS policy, 26.3 should leave around March 2027 and 26.8 around August 2027.

26.1, 26.2 and 26.4 to 26.6

No CVE has been published against these releases, but they are out of the stable window, so any future fix will not be backported to them. The nearest supported targets are 26.7 or 26.8 LTS.

25.x, including 25.3 and 25.8 LTS

25.8 LTS had a release as late as 26 August 2026, but it is now outside the supported list. 25.1 has the CVE-2025-1385 fix from 25.1.5.5, and the later 25.x releases are not named in that CVE record. A rolling upgrade from 25.3 or 25.8 goes through 26.3 on the way to 26.8; see upgrading ClickHouse LTS releases.

24.x

The last 24.3 and 24.8 LTS releases, 24.3.18.7 and 24.8.14.39, both came out on 19 February 2025 and carry the CVE-2025-1385 fix. The other 24.x lines had no fix published for it. A rolling upgrade from 24.x to a supported release needs intermediate stops.

23.x and older

The 2023 codec fixes were published for 23.3, 23.8, 23.9 and 23.10 only, so lines such as 23.1, 23.2 and 23.4 to 23.7 and every 22.x and older release lack them. Those are the unauthenticated crashes on the native port, and on these releases they have no fix at all. The ZooKeeper ensemble under replicated tables has its own CVE list; see ClickHouse and ZooKeeper and ZooKeeper vulnerabilities by version.

What to do on each line

  • Supported releases. Take the latest patch for your line, and for a cluster that upgrades once a year, prefer 26.8 LTS.
  • Unsupported 26.x and 25.x. Move to 26.8 LTS or 26.9, or take patched builds from a supplier that backports fixes. Until then, keep the native and HTTP ports, 9000 and 8123 by default, off untrusted networks.
  • 24.x and older. Plan the intermediate upgrade stops, or take patched builds. Until then, keep ports 9000 and 8123 internal, remove the library_bridge configuration if you do not use it, revoke the URL privilege from users who do not need url(), and do not use the query cache where applications switch roles.

Replicated tables also depend on a coordination service, so plan its upgrade alongside the server; see ClickHouse Keeper vs ZooKeeper.

Where OSSeva fits

OSSeva ships patched, signed builds for ClickHouse releases outside the community support window, including 24.x and older, every 25.x release with the 25.3 and 25.8 LTS lines, and 26.1, 26.2 and 26.4 to 26.6. They keep the same on-disk format, cover bundled library and toolchain CVEs, and come as Deb and RPM packages, Docker images and tarballs, with patched ZooKeeper 3.4 to 3.7 builds for the coordination ensemble. OSSeva backports fixes of this class to the end-of-life release lines it patches. They are available now on the Patch, Assure and Operate tiers. Assure adds a replication, sharding and coordination topology review, a ZooKeeper ACL, SASL and exposure audit, a ClickHouse Keeper migration plan with a tested runbook and an upgrade plan to a supported stable or LTS release, and Operate adds 24/7 replication queue, merge and Keeper quorum monitoring with a 15-minute P1 response, a named senior ClickHouse engineer and release upgrades executed shard by shard. See ClickHouse support and ClickHouse extended support.

Tags

ClickHouseCVEClickHouse LTSClickHouse 25.xEnd of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.