Skip to content
Grafana LabsCVE-2026-19854

Grafana Labs Clickhouse Datasource: cleartext transmission

Medium6.1CVE-2026-19854 · Published Aug 27, 2026 · updated Aug 31, 2026

When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connection library ignores that and talks to ClickHouse in the clear. Username, password, queries, and results can be read on the hop after the proxy. The server certificate is never checked, and a configured client certificate is not sent.

Grafana Labs advisory

Affected versions

PackageAffectedFixed in
Clickhouse Datasource
Product
>= 3.1.0, <= 4.20.0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-319

More Grafana Labs advisories

All Grafana Labs
Advisory
Grafana OSS: denial of service
Medium6.5Sep 2
Grafana: authentication bypass
High7.1Sep 2
Grafana Enterprise: capture-replay
Medium6.8Sep 2
Grafana Labs Alloy: exposed files
High7.7Aug 27
Grafana: improper access control
Medium6.3Aug 26
Grafana OSS: cross-site scripting
Medium6.8Aug 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.