Vulnerability in ClickHouse Plugin for Grafana by Grafana Labs
CVE-2026-19854
6.1MEDIUM
What is CVE-2026-19854?
A security flaw in the ClickHouse plugin for Grafana arises when it utilizes the Native protocol combined with a PDC or secure SOCKS configuration. The plugin requests a TLS connection; however, the underlying connection library does not honor this request and transmits data unencrypted. Consequently, sensitive information such as usernames, passwords, queries, and results can be intercepted during transmission. Furthermore, the server's certificate is not validated, and any configured client certificate fails to transmit, significantly compromising data integrity and confidentiality.
Affected Version(s)
Clickhouse Datasource 3.1.0 <= 4.20.0