VDB

JLSEC-2026-24

JLSEC-2026-24 PUBLISHED CVSS 4.599999904632568 MEDIUM

It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the `search_path` during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.

Risk Scores

CVSS 2.0
4.599999904632568

Affected Products

VendorProductVersions
JuliaLibPQ_jll0, 0
JuliaLibPQ_jll0

Timeline

  • Apr 3, 2026 CVE Published
  • Jul 25, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›