CVE 9.8 CRITICAL

Marten has an SQL injection vulnerability in its full-text search regConfig parameter_CVE-2026-45288

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-supplied regConfig parameter directly into the generated SQL without parameterization or validation, making every code path that exposes regConfig to untrusted input a SQL injection sink. This vulnerability is fixed in 8.36.1.

AI Analysis

SQL injection vulnerability in Marten's full-text search regConfig parameter

Basic Information

ID CVE-2026-45288
Source GitHub_M
Published May 28, 2026 at 20:20

Affected Product

Vendor JasperFx
Product marten
Version < 8.36.1
Affected Versions JasperFx marten < 8.36.1

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor JasperFx
Product Marten
Version < 8.36.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.