On 21 Dec a vulnerability was reported to CrateDB regarding authentication that could potentially affect all users. We have taken immediate action to remediate and have posted details here: Disable trust of HTTP ``X-Real-IP`` header by default. The CrateDB team currently has no evidence that the issue was exploited or data inappropriately disclosed. Customers are encouraged to implement recommended mitigations while we continue to investigate and monitor the situation.
Related Posts

CrateDB Advisory #17278
2025-02-06CrateDB users should upgrade to 5.9.9, 5.8.6, or 5.7.6 to avoid a potential data loss issue that may occur when the maximum amount of shards per node limit has been changed.

We've Achieved SOC 2 Type 2 Compliance!
2024-07-19We are proud to announce that we have successfully completed our SOC 2 Type 2 examination and achieved compliance of CrateDB on Azure and AWS. This accomplishment, in addition to our existing ISO 2700...

CrateDB Achieves ISO 27001 Certification
2023-08-29We are thrilled to announce that CrateDB has earned the ISO/IEC 27001:2013 certification for its CrateDB Cloud SaaS offering on Azure and AWS. This remarkable achievement represents a major milestone ...