Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40906

Опубликовано: 21 апр. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API is vulnerable to error-based SQL injection, allowing any authenticated user to read, write, and destroy the full contents of the underlying PostgreSQL database through crafted ORDER BY expressions. This vulnerability is fixed in 1.5.0.

A flaw was found in ElectricSQL, a Postgres sync engine. An authenticated user could exploit an error-based SQL injection vulnerability in the /v1/shape API's order_by parameter. This flaw allows an attacker to read, write, and destroy the full contents of the underlying PostgreSQL database. Such an attack could lead to severe data compromise and potential data loss.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processorNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-89
https://bugzilla.redhat.com/show_bug.cgi?id=2460291electric-sql: ElectricSQL: Critical data compromise and loss via SQL injection

EPSS

Процентиль: 38%
0.00461
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.9
nvd
4 месяца назад

Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API is vulnerable to error-based SQL injection, allowing any authenticated user to read, write, and destroy the full contents of the underlying PostgreSQL database through crafted ORDER BY expressions. This vulnerability is fixed in 1.5.0.

EPSS

Процентиль: 38%
0.00461
Низкий

8.8 High

CVSS3