CVE-2026-15741

Published: August 18, 2026Last modified: August 24, 2026

Description

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

Severity score breakdown

ParameterValue
Base score8.8
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSpostgresql15Unknown (15.2-r0)
25 LTSpostgresql17Fixed (17.11-r0)
Streampostgresql15Unknown (15.3-r0)
postgresql17Unknown (17.0-r1)
postgresql18Fixed (18.6-r0)

References

ON THIS PAGE