VDB

JLSEC-2026-34

JLSEC-2026-34 PUBLISHED CVSS 3.5 LOW

An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read.

Risk Scores

CVSS 2.0
3.5

Affected Products

VendorProductVersions
JuliaLibPQ_jll0, 0
JuliaLibPQ_jll0

Timeline

  • Apr 3, 2026 CVE Published
  • Jul 18, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›