Skip to content

starrocks

Data Warehouses & Analytics

An open-source, sub‑second query engine for ad‑hoc analytics on and off the data lakehouse

Java Latest 3.5.20 · 3d ago Security brief →

Features

  • Native vectorized SQL engine delivering 5–10× faster multi‑dimensional queries
  • Full ANSI SQL support with MySQL protocol compatibility for existing BI tools
  • Cost‑based optimizer (CBO) for smart query planning and efficiency gains

Security Response History

7 CVEs
CVE Severity Disclosed Patched (this tool) vs Ecosystem Median
CVE-2025-24813 KEV critical
CVSS 9.8
2025-04-01 2026-01-06 9mo / median 9mo
CVE-2023-44487 KEV medium
CVSS 7.5
2023-10-10 2026-01-06 2y 3mo / median 2y 3mo
CVE-2021-45046 KEV critical
CVSS 9.0
2023-05-01 2026-01-06 2y 8mo / median 2y 9mo
CVE-2017-12617 KEV high
CVSS 8.1
2022-03-25 2026-01-06 3y 10mo / median 3y 10mo
CVE-2017-12615 KEV high
CVSS 8.1
2022-03-25 2026-01-06 3y 10mo / median 3y 10mo
CVE-2020-1938 KEV critical
CVSS 9.8
2022-03-03 2026-01-06 3y 10mo / median 3y 10mo
CVE-2021-44228 KEV critical
CVSS 10.0
2021-12-10 2026-01-06 4y 1mo / median 4y 2mo

Recent releases

View all 20 releases →
Review required
3.5.20 Breaking risk
Breaking upgrade

Iceberg catalog behavior, GIN predicate change, FE metric

Upgrade now
4.0.13 Breaking risk
Dependencies

LIKE escape change + security upgrades

Upgrade now
3.5.19 Breaking risk
Breaking upgrade RCE / SSRF

parse_json behavior, Arrow lists, stats config, bug fixes

Upgrade now
4.0.12 Mixed
Dependencies

Parquet timestamps, CTAS VARCHAR, Paimon splits

No immediate action
3.5.18 Mixed

SHOW in txn; UDAF cache; Hive stats handling

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
11,909
Forks
2,483
Languages
Java C++ Python

Install & Platforms

Platforms
linux

Community & Support

Alternative to

other popular alternatives

Beta — feedback welcome: [email protected]