CVE-2019-16535
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
30/12/2019
Last modified:
25/06/2025
Description
In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:* | 19.14 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



