Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-19854— CVE-2026-19854 CVE Record

Quick assessment

Affected
Grafana Clickhouse Datasource
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

当 ClickHouse 插件使用 Native 协议(默认)配合 PDC 或安全的 SOCKS 代理时,客户端请求启用 TLS,但底层连接库会忽略该请求,并以明文方式与 ClickHouse 进行通信。因此,在代理服务器之后的一跳网络中,用户名、密码、查询语句及查询结果均可能被窃听。此外,服务器证书从未被验证,且已配置的客户证书也未被发送。

CVSS 6.1 · Medium

Possible ATT&CK Techniques 2 AI

T1129 · Shared Modules T1019

Affected Version Matrix 1

VendorProduct Version RangeStatus
Grafana Clickhouse Datasource 3.1.0≤ 4.20.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19854

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CVE-2026-19854 CVE Record
Source: CVE Program / CVE List V5
Vulnerability Description
When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connection library ignores that and talks to ClickHouse in the clear. Username, password, queries, and results can be read on the hop after the proxy. The server certificate is never checked, and a configured client certificate is not sent.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
敏感数据的明文传输
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Grafana Clickhouse Datasource 3.1.0 ~ 4.20.0 -

II. Public POCs for CVE-2026-19854

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19854

登录查看更多情报信息。

Vendor Advisories for CVE-2026-19854 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-19854

No comments yet


Leave a comment