ClickHouse — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
November 19, 2025
Last Seen
July 11, 2026

ClickHouse is a technology platform tracked across 3 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed November 19, 2025; most recent activity July 11, 2026.

Related Threat Clusters

  • CVE-2026-55879: Critical XSS Vulnerability in OpenReplay Leads to Account Takeover

    CVE-2026-55879 is a critical vulnerability affecting OpenReplay versions 1.24.0 to 1.25.0, allowing unauthenticated attackers to execute stored XSS in the dashboard. The flaw arises from the OpenReplay tracking SDK's…

    3 articles · Updated July 11, 2026
  • Cloudflare Outage Disrupts Major Websites and Apps

    A significant outage at Cloudflare has resulted in numerous major websites and applications going offline. The incident has particularly impacted financial services firms that rely on Cloudflare's network and security…

    36 articles · Updated November 18, 2025
  • Cloudflare Outage Disrupts Major Internet Services

    On November 18, 2025, Cloudflare experienced a significant outage that affected access to numerous major websites, including ChatGPT and X. The disruption was caused by a change to database access controls, which led to…

    39 articles · Updated November 26, 2025

Recent Intelligence Reports

  • CVE-2026-55879 AKAOMA CVE VULNERABILITIES / 18h OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom event names and captured page URLs from any visitor using a public project key, stores them in ClickHouse without output encoding, and later renders them in the authenticated dashboard through TextEllipsis and the event-details modal, allowing an unauthenticated attacker to store script that executes in the dashboard origin, reads — cve.akaoma.com · July 11, 2026
  • CVE-2026-55879 - OpenReplay: Unauthenticated stored XSS leads to dashboard account takeover Latest High/Critical Vulnerabilitiy Feed / 18h CVE ID : CVE-2026-55879 Published : July 10, 2026, 9:16 p.m. 10 hours, 30 minutes ago Description : OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom event names and captured page URLs from any visitor using a public project key, stores them in ClickHouse without output encoding, and later — cvefeed.io · July 11, 2026
  • CVE-2026-55879 - Exploits & Severity — Feedly · July 11, 2026
  • Cloudflare explains how it took down large chunks of the internet — 9To5Mac · November 19, 2025
  • Cloudflare broke the internet with a bad DB query — Theregister · November 19, 2025
  • Cloudflare contrite after worst outage since 2019 — Computerweekly · November 19, 2025

CVSS v3.1 Breakdown