Back

HIGH

OneUptime: ClickHouse SQL Injection via unvalidated column identifiers in sort, select, and groupBy parameters

Published Mar 20, 2026

Description

OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-32306 (ClickHouse SQL injection via aggregate query parameters) added column name validation to the _aggregateBy method but did not apply the same validation to three other query construction paths in StatementGenerator. The toSortStatement, toSelectStatement, and toGroupByStatement methods accept user-controlled object keys from API request bodies and interpolate them as ClickHouse Identifier parameters without verifying they correspond to actual model columns. ClickHouse Identifier parameters are substituted directly into queries without escaping, so an attacker who can reach any analytics list or aggregate endpoint can inject arbitrary SQL through crafted sort, select, or groupBy keys. This issue has been patched in version 10.0.34.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Mar 20, 2026
Updated Mar 25, 2026
Reserved Mar 17, 2026
CISA Vulnrichment
Updated Mar 25, 2026
NVD
Status Analyzed
Modified Oct 7, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Mar 20, 2026
Updated Mar 25, 2026
Exploited since n/a
EUVD-2026-13778 GHSA-GCG3-C5P2-CQGG