CVE 3.7 LOW

PostgreSQL REFRESH PUBLICATION allows SQL injection via table name_CVE-2026-6638

3.7 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

Description

SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.

Basic Information

ID CVE-2026-6638
Source PostgreSQL
Published May 14, 2026 at 13:00

Affected Product

Vendor n/a
Product PostgreSQL
Version 18
Affected Versions n/a PostgreSQL 18
n/a PostgreSQL 17
n/a PostgreSQL 16

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.