Search

Find a vulnerability

Search criteria

    Related vulnerabilities

    BREW-HARLEQUIN-CVE-2025-64429 (PYSEC-2025-112)

    Vulnerability from osv_homebrew – Published: 2026-08-13 16:55 – Updated: 2026-10-04 03:56 – Source website
    VLAI
    Details

    DuckDB is a SQL database management system. DuckDB implemented block-based encryption of DB on the filesystem starting with DuckDB 1.4.0. There are a few issues related to this implementation. The DuckDB can fall back to an insecure random number generator (pcg32) to generate cryptographic keys or IVs. When clearing keys from memory, the compiler may remove the memset() and leave sensitive data on the heap. By modifying the database header, an attacker could downgrade the encryption mode from GCM to CTR to bypass integrity checks. There may be a failure to check return value on call to OpenSSL rand_bytes(). An attacker could use public IVs to compromise the internal state of RNG and determine the randomly generated key used to encrypt temporary files, get access to cryptographic keys if they have access to process memory (e.g. through memory leak),circumvent GCM integrity checks, and/or influence the OpenSSL random number generator and DuckDB would not be able to detect a failure of the generator. Version 1.4.2 has disabled the insecure random number generator by no longer using the fallback to write to or create databases. Instead, DuckDB will now attempt to install and load the OpenSSL implementation in the httpfs extension. DuckDB now uses secure MbedTLS primitive to clear memory as recommended and requires explicit specification of ciphers without integrity checks like CTR on ATTACH. Additionally, DuckDB now checks the return code.


    {
      "affected": [
        {
          "ecosystem_specific": {
            "fix": "bump",
            "range_state": "fixed",
            "resource": "duckdb",
            "resource_purl": "pkg:pypi/duckdb@1.5.6",
            "upstream_fixed_in": "1.4.2"
          },
          "package": {
            "ecosystem": "Homebrew",
            "name": "harlequin",
            "purl": "pkg:brew/harlequin"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "2.3.0"
                },
                {
                  "fixed": "2.4.0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "database_specific": {
        "confidence": "high",
        "source": "matched",
        "strategy": "registry",
        "upstream_evidence": [
          {
            "ecosystem": "PyPI",
            "key": "pkg:pypi/duckdb@1.5.6",
            "name": "duckdb",
            "resource": "duckdb",
            "strategy": "registry",
            "subject_version": "1.5.6"
          }
        ]
      },
      "details": "DuckDB is a SQL database management system. DuckDB implemented block-based encryption of DB on the filesystem starting with DuckDB 1.4.0. There are a few issues related to this implementation. The DuckDB can fall back to an insecure random number generator (pcg32) to generate cryptographic keys or IVs. When clearing keys from memory, the compiler may remove the memset() and leave sensitive data on the heap. By modifying the database header, an attacker could downgrade the encryption mode from GCM to CTR to bypass integrity checks. There may be a failure to check return value on call to OpenSSL `rand_bytes()`. An attacker could use public IVs to compromise the internal state of RNG and determine the randomly generated key used to encrypt temporary files, get access to cryptographic keys if they have access to process memory (e.g. through memory leak),circumvent GCM integrity checks, and/or influence the OpenSSL random number generator and DuckDB would not be able to detect a failure of the generator. Version 1.4.2 has disabled the insecure random number generator by no longer using the fallback to write to or create databases. Instead, DuckDB will now attempt to install and load the OpenSSL implementation in the `httpfs` extension. DuckDB now uses secure MbedTLS primitive to clear memory as recommended and requires explicit specification of ciphers without integrity checks like CTR on `ATTACH`. Additionally, DuckDB now checks the return code.",
      "id": "BREW-harlequin-CVE-2025-64429",
      "modified": "2026-10-04T03:56:47Z",
      "published": "2026-08-13T16:55:40Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/duckdb/duckdb/blob/029a5b87ff5b1cd22f7f9717d48cd8830d00807c/src/common/random_engine.cpp#L20"
        },
        {
          "type": "ADVISORY",
          "url": "https://duckdb.org/2025/09/16/announcing-duckdb-140.html"
        },
        {
          "type": "ADVISORY",
          "url": "https://github.com/duckdb/duckdb/security/advisories/GHSA-vmp8-hg63-v2hp"
        },
        {
          "type": "FIX",
          "url": "https://github.com/duckdb/duckdb/pull/17275"
        }
      ],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
          "type": "CVSS_V3"
        }
      ],
      "upstream": [
        "PYSEC-2025-112",
        "CVE-2025-64429",
        "GHSA-vmp8-hg63-v2hp"
      ]
    }

    BREW-MCPM-CVE-2025-64429 (PYSEC-2025-112)

    Vulnerability from osv_homebrew – Published: 2026-08-13 17:13 – Updated: 2026-10-04 12:45 – Source website
    VLAI
    Details

    DuckDB is a SQL database management system. DuckDB implemented block-based encryption of DB on the filesystem starting with DuckDB 1.4.0. There are a few issues related to this implementation. The DuckDB can fall back to an insecure random number generator (pcg32) to generate cryptographic keys or IVs. When clearing keys from memory, the compiler may remove the memset() and leave sensitive data on the heap. By modifying the database header, an attacker could downgrade the encryption mode from GCM to CTR to bypass integrity checks. There may be a failure to check return value on call to OpenSSL rand_bytes(). An attacker could use public IVs to compromise the internal state of RNG and determine the randomly generated key used to encrypt temporary files, get access to cryptographic keys if they have access to process memory (e.g. through memory leak),circumvent GCM integrity checks, and/or influence the OpenSSL random number generator and DuckDB would not be able to detect a failure of the generator. Version 1.4.2 has disabled the insecure random number generator by no longer using the fallback to write to or create databases. Instead, DuckDB will now attempt to install and load the OpenSSL implementation in the httpfs extension. DuckDB now uses secure MbedTLS primitive to clear memory as recommended and requires explicit specification of ciphers without integrity checks like CTR on ATTACH. Additionally, DuckDB now checks the return code.


    {
      "affected": [
        {
          "ecosystem_specific": {
            "fix": "bump",
            "range_state": "fixed",
            "resource": "duckdb",
            "resource_purl": "pkg:pypi/duckdb@1.5.6",
            "upstream_fixed_in": "1.4.2"
          },
          "package": {
            "ecosystem": "Homebrew",
            "name": "mcpm",
            "purl": "pkg:brew/mcpm"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "2.8.2"
                },
                {
                  "fixed": "2.9.0_2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "database_specific": {
        "confidence": "high",
        "source": "matched",
        "strategy": "registry",
        "upstream_evidence": [
          {
            "ecosystem": "PyPI",
            "key": "pkg:pypi/duckdb@1.5.6",
            "name": "duckdb",
            "resource": "duckdb",
            "strategy": "registry",
            "subject_version": "1.5.6"
          }
        ]
      },
      "details": "DuckDB is a SQL database management system. DuckDB implemented block-based encryption of DB on the filesystem starting with DuckDB 1.4.0. There are a few issues related to this implementation. The DuckDB can fall back to an insecure random number generator (pcg32) to generate cryptographic keys or IVs. When clearing keys from memory, the compiler may remove the memset() and leave sensitive data on the heap. By modifying the database header, an attacker could downgrade the encryption mode from GCM to CTR to bypass integrity checks. There may be a failure to check return value on call to OpenSSL `rand_bytes()`. An attacker could use public IVs to compromise the internal state of RNG and determine the randomly generated key used to encrypt temporary files, get access to cryptographic keys if they have access to process memory (e.g. through memory leak),circumvent GCM integrity checks, and/or influence the OpenSSL random number generator and DuckDB would not be able to detect a failure of the generator. Version 1.4.2 has disabled the insecure random number generator by no longer using the fallback to write to or create databases. Instead, DuckDB will now attempt to install and load the OpenSSL implementation in the `httpfs` extension. DuckDB now uses secure MbedTLS primitive to clear memory as recommended and requires explicit specification of ciphers without integrity checks like CTR on `ATTACH`. Additionally, DuckDB now checks the return code.",
      "id": "BREW-mcpm-CVE-2025-64429",
      "modified": "2026-10-04T12:45:45Z",
      "published": "2026-08-13T17:13:14Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/duckdb/duckdb/blob/029a5b87ff5b1cd22f7f9717d48cd8830d00807c/src/common/random_engine.cpp#L20"
        },
        {
          "type": "ADVISORY",
          "url": "https://duckdb.org/2025/09/16/announcing-duckdb-140.html"
        },
        {
          "type": "ADVISORY",
          "url": "https://github.com/duckdb/duckdb/security/advisories/GHSA-vmp8-hg63-v2hp"
        },
        {
          "type": "FIX",
          "url": "https://github.com/duckdb/duckdb/pull/17275"
        }
      ],
      "schema_version": "1.7.3",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
          "type": "CVSS_V3"
        }
      ],
      "upstream": [
        "PYSEC-2025-112",
        "CVE-2025-64429",
        "GHSA-vmp8-hg63-v2hp"
      ]
    }

    CVE-2025-64429 (GCVE-0-2025-64429)

    Vulnerability from cvelistv5 – Published: 2025-11-12 21:32 – Updated: 2025-11-13 16:45
    VLAI
    Title
    DuckDB Encryption Crypto implementation is vulnerable
    Summary
    DuckDB is a SQL database management system. DuckDB implemented block-based encryption of DB on the filesystem starting with DuckDB 1.4.0. There are a few issues related to this implementation. The DuckDB can fall back to an insecure random number generator (pcg32) to generate cryptographic keys or IVs. When clearing keys from memory, the compiler may remove the memset() and leave sensitive data on the heap. By modifying the database header, an attacker could downgrade the encryption mode from GCM to CTR to bypass integrity checks. There may be a failure to check return value on call to OpenSSL `rand_bytes()`. An attacker could use public IVs to compromise the internal state of RNG and determine the randomly generated key used to encrypt temporary files, get access to cryptographic keys if they have access to process memory (e.g. through memory leak),circumvent GCM integrity checks, and/or influence the OpenSSL random number generator and DuckDB would not be able to detect a failure of the generator. Version 1.4.2 has disabled the insecure random number generator by no longer using the fallback to write to or create databases. Instead, DuckDB will now attempt to install and load the OpenSSL implementation in the `httpfs` extension. DuckDB now uses secure MbedTLS primitive to clear memory as recommended and requires explicit specification of ciphers without integrity checks like CTR on `ATTACH`. Additionally, DuckDB now checks the return code.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-11-13 16:45 UTC
    CWE
    • CWE-327 - Use of a Broken or Risky Cryptographic Algorithm
    Impacted products
    Vendor Product Version
    duckdb duckdb Affected: >= 1.4.0, < 1.4.2
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-64429",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-11-13T16:45:32.309589Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-11-13T16:45:43.375Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "duckdb",
              "vendor": "duckdb",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003e= 1.4.0, \u003c 1.4.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "DuckDB is a SQL database management system. DuckDB implemented block-based encryption of DB on the filesystem starting with DuckDB 1.4.0. There are a few issues related to this implementation. The DuckDB can fall back to an insecure random number generator (pcg32) to generate cryptographic keys or IVs. When clearing keys from memory, the compiler may remove the memset() and leave sensitive data on the heap. By modifying the database header, an attacker could downgrade the encryption mode from GCM to CTR to bypass integrity checks. There may be a failure to check return value on call to OpenSSL `rand_bytes()`. An attacker could use public IVs to compromise the internal state of RNG and determine the randomly generated key used to encrypt temporary files, get access to cryptographic keys if they have access to process memory (e.g. through memory leak),circumvent GCM integrity checks, and/or influence the OpenSSL random number generator and DuckDB would not be able to detect a failure of the generator. Version 1.4.2 has disabled the insecure random number generator by no longer using the fallback to write to or create databases. Instead, DuckDB will now attempt to install and load the OpenSSL implementation in the `httpfs` extension. DuckDB now uses secure MbedTLS primitive to clear memory as recommended and requires explicit specification of ciphers without integrity checks like CTR on `ATTACH`. Additionally, DuckDB now checks the return code."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-327",
                  "description": "CWE-327: Use of a Broken or Risky Cryptographic Algorithm",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-11-12T21:32:45.663Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/duckdb/duckdb/security/advisories/GHSA-vmp8-hg63-v2hp",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/duckdb/duckdb/security/advisories/GHSA-vmp8-hg63-v2hp"
            },
            {
              "name": "https://github.com/duckdb/duckdb/pull/17275",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/duckdb/duckdb/pull/17275"
            },
            {
              "name": "https://duckdb.org/2025/09/16/announcing-duckdb-140.html",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://duckdb.org/2025/09/16/announcing-duckdb-140.html"
            },
            {
              "name": "https://github.com/duckdb/duckdb/blob/029a5b87ff5b1cd22f7f9717d48cd8830d00807c/src/common/random_engine.cpp#L20",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/duckdb/duckdb/blob/029a5b87ff5b1cd22f7f9717d48cd8830d00807c/src/common/random_engine.cpp#L20"
            }
          ],
          "source": {
            "advisory": "GHSA-vmp8-hg63-v2hp",
            "discovery": "UNKNOWN"
          },
          "title": "DuckDB Encryption Crypto implementation is vulnerable"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2025-64429",
        "datePublished": "2025-11-12T21:32:45.663Z",
        "dateReserved": "2025-11-03T22:12:51.364Z",
        "dateUpdated": "2025-11-13T16:45:43.375Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    PYSEC-2025-112

    Vulnerability from pysec - Published: 2025-11-12 22:15 - Updated: 2026-05-20 09:18
    VLAI
    Details

    DuckDB is a SQL database management system. DuckDB implemented block-based encryption of DB on the filesystem starting with DuckDB 1.4.0. There are a few issues related to this implementation. The DuckDB can fall back to an insecure random number generator (pcg32) to generate cryptographic keys or IVs. When clearing keys from memory, the compiler may remove the memset() and leave sensitive data on the heap. By modifying the database header, an attacker could downgrade the encryption mode from GCM to CTR to bypass integrity checks. There may be a failure to check return value on call to OpenSSL rand_bytes(). An attacker could use public IVs to compromise the internal state of RNG and determine the randomly generated key used to encrypt temporary files, get access to cryptographic keys if they have access to process memory (e.g. through memory leak),circumvent GCM integrity checks, and/or influence the OpenSSL random number generator and DuckDB would not be able to detect a failure of the generator. Version 1.4.2 has disabled the insecure random number generator by no longer using the fallback to write to or create databases. Instead, DuckDB will now attempt to install and load the OpenSSL implementation in the httpfs extension. DuckDB now uses secure MbedTLS primitive to clear memory as recommended and requires explicit specification of ciphers without integrity checks like CTR on ATTACH. Additionally, DuckDB now checks the return code.

    Impacted products
    Name purl
    duckdb pkg:pypi/duckdb

    {
      "affected": [
        {
          "package": {
            "ecosystem": "PyPI",
            "name": "duckdb",
            "purl": "pkg:pypi/duckdb"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "1.4.0"
                },
                {
                  "fixed": "1.4.2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "1.4.0",
            "1.4.1"
          ]
        }
      ],
      "aliases": [
        "CVE-2025-64429",
        "GHSA-vmp8-hg63-v2hp"
      ],
      "details": "DuckDB is a SQL database management system. DuckDB implemented block-based encryption of DB on the filesystem starting with DuckDB 1.4.0. There are a few issues related to this implementation. The DuckDB can fall back to an insecure random number generator (pcg32) to generate cryptographic keys or IVs. When clearing keys from memory, the compiler may remove the memset() and leave sensitive data on the heap. By modifying the database header, an attacker could downgrade the encryption mode from GCM to CTR to bypass integrity checks. There may be a failure to check return value on call to OpenSSL `rand_bytes()`. An attacker could use public IVs to compromise the internal state of RNG and determine the randomly generated key used to encrypt temporary files, get access to cryptographic keys if they have access to process memory (e.g. through memory leak),circumvent GCM integrity checks, and/or influence the OpenSSL random number generator and DuckDB would not be able to detect a failure of the generator. Version 1.4.2 has disabled the insecure random number generator by no longer using the fallback to write to or create databases. Instead, DuckDB will now attempt to install and load the OpenSSL implementation in the `httpfs` extension. DuckDB now uses secure MbedTLS primitive to clear memory as recommended and requires explicit specification of ciphers without integrity checks like CTR on `ATTACH`. Additionally, DuckDB now checks the return code.",
      "id": "PYSEC-2025-112",
      "modified": "2026-05-20T09:18:59.601738Z",
      "published": "2025-11-12T22:15:49.813Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/duckdb/duckdb/blob/029a5b87ff5b1cd22f7f9717d48cd8830d00807c/src/common/random_engine.cpp#L20"
        },
        {
          "type": "ADVISORY",
          "url": "https://duckdb.org/2025/09/16/announcing-duckdb-140.html"
        },
        {
          "type": "ADVISORY",
          "url": "https://github.com/duckdb/duckdb/security/advisories/GHSA-vmp8-hg63-v2hp"
        },
        {
          "type": "FIX",
          "url": "https://github.com/duckdb/duckdb/pull/17275"
        }
      ],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
          "type": "CVSS_V3"
        }
      ]
    }