VDB
JLSEC-2026-52
JLSEC-2026-52
PUBLISHED
CVSS 7.5 HIGH
Time-of-check Time-of-use (TOCTOU) race condition in `pg_dump` in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running `pg_dump`, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for `pg_dump` to start, but winning the race condition is trivial if the attacker retains an open transaction. Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are affected.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Julia | LibPQ_jll | 0, 0 |
| Julia | LibPQ_jll | 0 |
Timeline
- Apr 3, 2026 CVE Published
- Jul 25, 2026 CVE Updated