← Voltar à pesquisa de CVEs

CVE-2026-6464

PostgreSQL

Descrição

Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the -COPY FROM STDIN- or -\copy FROM STDIN- command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. -COPY FROM- with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don-t control. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS 8.1EPSS 0.358%Risco 0.84
Ver fonte
Publicação
2026-08-13 13:19:16
Versões afetadas
<18.5, <17.11, <16.15, <15.19, <14.24
Tipo
Biblioteca
Última alteração
2026-08-19 15:01:29
Vetor
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H