Количество 24
Количество 24
BDU:2026-07093
Уязвимость реализации команды ALTER SUBSCRIPTION ... REFRESH PUBLICATION системы управления базами данных PostgreSQL, позволяющая нарушителю выполнить произвольные SQL-запросы
ROS-20260706-73-0059
Уязвимость postgresql18-1c
ROS-20260706-73-0058
Уязвимость postgresql18
ROS-20260706-73-0057
Уязвимость postgresql17-1c
ROS-20260706-73-0056
Уязвимость postgresql16
ROS-20260706-73-0055
Уязвимость postgresql17
CVE-2026-6638
SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.
CVE-2026-6638
SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.
CVE-2026-6638
SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.
CVE-2026-6638
PostgreSQL REFRESH PUBLICATION allows SQL injection via table name
CVE-2026-6638
SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... ...
GHSA-3835-x2rj-c3qj
SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.
openSUSE-SU-2026:21104-1
Security update for postgresql16
SUSE-SU-2026:2084-1
Security update for postgresql16
SUSE-SU-2026:2001-1
Security update for postgresql16
SUSE-SU-2026:1942-1
Security update for postgresql16
openSUSE-SU-2026:20970-1
Security update for postgresql17
SUSE-SU-2026:2303-1
Security update for postgresql17
SUSE-SU-2026:1943-1
Security update for postgresql17
openSUSE-SU-2026:20901-1
Security update for postgresql18
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-07093 Уязвимость реализации команды ALTER SUBSCRIPTION ... REFRESH PUBLICATION системы управления базами данных PostgreSQL, позволяющая нарушителю выполнить произвольные SQL-запросы | CVSS3: 3.7 | 0% Низкий | 3 месяца назад | |
ROS-20260706-73-0059 Уязвимость postgresql18-1c | CVSS3: 3.7 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0058 Уязвимость postgresql18 | CVSS3: 3.7 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0057 Уязвимость postgresql17-1c | CVSS3: 3.7 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0056 Уязвимость postgresql16 | CVSS3: 3.7 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0055 Уязвимость postgresql17 | CVSS3: 3.7 | 0% Низкий | 25 дней назад | |
CVE-2026-6638 SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected. | CVSS3: 3.7 | 0% Низкий | 3 месяца назад | |
CVE-2026-6638 SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected. | CVSS3: 3.7 | 0% Низкий | 3 месяца назад | |
CVE-2026-6638 SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected. | CVSS3: 3.7 | 0% Низкий | 3 месяца назад | |
CVE-2026-6638 PostgreSQL REFRESH PUBLICATION allows SQL injection via table name | CVSS3: 3.7 | 0% Низкий | 3 месяца назад | |
CVE-2026-6638 SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... ... | CVSS3: 3.7 | 0% Низкий | 3 месяца назад | |
GHSA-3835-x2rj-c3qj SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected. | CVSS3: 3.7 | 0% Низкий | 3 месяца назад | |
openSUSE-SU-2026:21104-1 Security update for postgresql16 | около 1 месяца назад | |||
SUSE-SU-2026:2084-1 Security update for postgresql16 | 2 месяца назад | |||
SUSE-SU-2026:2001-1 Security update for postgresql16 | 2 месяца назад | |||
SUSE-SU-2026:1942-1 Security update for postgresql16 | 2 месяца назад | |||
openSUSE-SU-2026:20970-1 Security update for postgresql17 | около 1 месяца назад | |||
SUSE-SU-2026:2303-1 Security update for postgresql17 | около 2 месяцев назад | |||
SUSE-SU-2026:1943-1 Security update for postgresql17 | 2 месяца назад | |||
openSUSE-SU-2026:20901-1 Security update for postgresql18 | около 2 месяцев назад |
Уязвимостей на страницу