Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19496

Опубликовано: 23 июл. 2026
Источник: redhat
CVSS3: 8.8

Описание

A flaw was found in sources-api-go. An authenticated remote user can exploit a SQL injection vulnerability by injecting arbitrary SQL expressions through query parameter filtering. This can lead to unauthorized information disclosure of internal database fields, arbitrary PostgreSQL function execution, and denial of service.

Отчет

This Important SQL injection vulnerability in sources-api-go allows an authenticated console.redhat.com user to execute arbitrary SQL expressions. This could lead to sensitive information disclosure, arbitrary PostgreSQL function execution, and denial of service, making it a significant risk for Red Hat cloud services. The flaw stems from unsanitized user input being directly interpolated into database queries.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-89
https://bugzilla.redhat.com/show_bug.cgi?id=2513586sources-api-go: sources-api-go: SQL injection (CWE-89) in query parameter filtering — unsanitised user input interpolated into WHERE clause

8.8 High

CVSS3

8.8 High

CVSS3

Уязвимость CVE-2026-19496