← Zurück zur CVE-Suche

CVE-2026-32687

elixir-ecto

Beschreibung

Improper Neutralization of Special Elements used in an SQL Command (-SQL Injection-) vulnerability in elixir-ecto postgrex (-Elixir.Postgrex.Notifications- module) allows SQL Injection. The channel argument passed to -Elixir.Postgrex.Notifications-:listen/3 and -Elixir.Postgrex.Notifications-:unlisten/3 is interpolated directly into LISTEN -...- / UNLISTEN -...- SQL statements without escaping the - character. An attacker who can influence the channel name can inject a - to break out of the quoted identifier and append arbitrary SQL. Because the notifications connection uses the PostgreSQL simple query protocol, multi-statement payloads are accepted, allowing DDL and DML commands to be chained (e.g. ; DROP TABLE ...; --). The same unsanitized interpolation also occurs in handle_connect/1 when replaying LISTEN commands after a reconnect. This vulnerability is associated with program file lib/postgrex/notifications.ex and program routines -Elixir.Postgrex.Notifications-:listen/3, -Elixir.Postgrex.Notifications-:unlisten/3, -Elixir.Postgrex.Notifications-:handle_connect/1. This issue affects postgrex: from 0.16.0 before 0.22.2.

CVSS 7.8EPSS 0.198%Risiko 0.79
Quelle öffnen
Veröffentlicht
2026-05-12 15:16:12
Betroffene Versionen
unknown
Typ
Package
Zuletzt geändert
2026-07-24 15:17:16
Vektor
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H