MonetDB Server Denial-of-Service Vulnerability in SQL Statement Processing

Vulnerability

A denial-of-service vulnerability has been identified in MonetDB Server version 11.47.11. The issue arises in the 'bind_col_exp' component, where attackers can cause the server to crash by using specially crafted SQL statements. This vulnerability can be reproduced by creating a table and then executing a SELECT query that includes complex ordering and aggregation functions, which leads to a server crash.

Impact

Exploitation of this vulnerability causes the MonetDB server to crash, disrupting any active database sessions and requiring the server to be restarted.

Reproduction

The vulnerability can be reproduced by creating a table and then executing a SELECT query that orders the results based on an average of a maximum value, using window functions and NULL handling. This can be done manually or automated with a script that runs inside a Docker container with MonetDB.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
2.5
exploitability
9.1
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.