๐Ÿ” CVE Alert

CVE-2026-19854

MEDIUM 6.1

CVE-2026-19854 CVE Record

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connection library ignores that and talks to ClickHouse in the clear. Username, password, queries, and results can be read on the hop after the proxy. The server certificate is never checked, and a configured client certificate is not sent.

CWE CWE-319
Vendor grafana
Product clickhouse datasource
Ecosystems
Industries
Technology
Published Aug 27, 2026
Stay Ahead of the Next One

Get instant alerts for grafana clickhouse datasource

Be the first to know when new medium vulnerabilities affecting grafana clickhouse datasource are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Grafana / Clickhouse Datasource
3.1.0 โ‰ค 4.20.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
grafana.com: https://grafana.com/security/security-advisories/cve-2026-19854