Grafana LabsCVE-2026-19854
Grafana Labs Clickhouse Datasource: cleartext transmission
Medium6.1CVE-2026-19854 · Published Aug 27, 2026 · updated Aug 31, 2026
When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connection library ignores that and talks to ClickHouse in the clear. Username, password, queries, and results can be read on the hop after the proxy. The server certificate is never checked, and a configured client certificate is not sent.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Clickhouse Datasource Product | >= 3.1.0, <= 4.20.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-319
More Grafana Labs advisories
All Grafana Labs| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 2 | Grafana OSS: denial of service | Medium6.5 | No fix yet |
| Sep 2 | Grafana: authentication bypass | High7.1 | No fix yet |
| Sep 2 | Grafana Enterprise: capture-replay | Medium6.8 | No fix yet |
| Aug 27 | Grafana Labs Alloy: exposed files | High7.7 | No fix yet |
| Aug 26 | Grafana: improper access control | Medium6.3 | OSS 12.4.8+2 more |
| Aug 24 | Grafana OSS: cross-site scripting | Medium6.8 | No fix yet |