MonetDB Server Denial-of-Service Vulnerability in exp_copy Component

Vulnerability

A denial-of-service vulnerability has been identified in MonetDB Server version 11.49.1, specifically within the exp_copy component. This issue allows attackers to cause the server to crash by sending crafted SQL statements. The vulnerability can be reproduced in a Docker container running Ubuntu 20.04.

Impact

Exploitation of this vulnerability leads to a crash of the MonetDB server process, causing a denial-of-service condition where the server is no longer available to handle requests.

Reproduction

The vulnerability can be reproduced by creating a table and then deleting from it with a SQL statement that includes a subquery. This crafted SQL statement causes the server to crash. The issue can be automated with a shell script that runs the SQL command using the MonetDB client, mclient, and then checks if the server process is still running.

Remediation

Users can update to the latest version of MonetDB Server, as this vulnerability has been addressed in the December 2023 release.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
2.5
exploitability
9.1
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.