Catalog / DuckDB

DuckDB security advisories

All 3 advisories DuckDB has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.

Advisories
32 carry a CVE
medium
3
Fix in the archive
2of 3 matched to a release
Oldest
23 Jul 20242.1 years ago

1 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Newest first

Every product
CVE-2024-41672medium

sniff_csv provides filesystem access even when enable_external_access is disabled

GHSA-w2gf-jxc9-pf2qFixed in 1.1.0
GHSA-7q92-pph9-5686medium

GitHub Actions expression injection vulnerability in CheckIssueForCodeFormatting workflow