CVE-2026-18408
Reported by PostgreSQL · Published August 13, 2026
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | PostgreSQL | 18, 17, 16 |
| alpine | postgresql15 | 0, 0, 0 |
| n/a | PostgreSQL | 0, 15, 16 |
| alpine | postgresql17 | 0, 0, 0 |
| alpine | postgresql16 | 0, 0, 0 |
| alpine | postgresql18 | 0, 0, 0 |
Timeline
- Aug 13, 2026 CVE Published
- Aug 15, 2026 Coalition ESS Score
- Aug 20, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 4, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 14, 2026 Distribution Patch
- Sep 14, 2026 Security Advisory
- Sep 16, 2026 EPSS Score