Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26

Количество 26

fstec логотип

BDU:2026-11972

около 1 месяца назад

Уязвимость утилиты pg_dump системы управления базами данных PostgreSQL, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2026-18408

около 1 месяца назад

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2026-18408

около 1 месяца назад

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.4
EPSS: Низкий
nvd логотип

CVE-2026-18408

около 1 месяца назад

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2026-18408

23 дня назад

PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2026-18408

около 1 месяца назад

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious s ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-p745-282f-cxpr

около 1 месяца назад

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21700-1

16 дней назад

Security update for postgresql15

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21699-1

16 дней назад

Security update for postgresql14

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4018-1

8 дней назад

Security update for postgresql15

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4017-1

8 дней назад

Security update for postgresql15

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3944-1

12 дней назад

Security update for postgresql14

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3941-1

12 дней назад

Security update for postgresql14

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3940-1

12 дней назад

Security update for postgresql15

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3793-1

21 день назад

Security update for postgresql14

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21702-1

16 дней назад

Security update for postgresql17

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21701-1

16 дней назад

Security update for postgresql16

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4016-1

8 дней назад

Security update for postgresql17

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4013-1

8 дней назад

Security update for postgresql17

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3963-1

12 дней назад

Security update for postgresql16

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-11972

Уязвимость утилиты pg_dump системы управления базами данных PostgreSQL, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-18408

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-18408

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.4
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-18408

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2026-18408

PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client

CVSS3: 8.8
0%
Низкий
23 дня назад
debian логотип
CVE-2026-18408

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious s ...

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-p745-282f-cxpr

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21700-1

Security update for postgresql15

16 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21699-1

Security update for postgresql14

16 дней назад
suse-cvrf логотип
SUSE-SU-2026:4018-1

Security update for postgresql15

8 дней назад
suse-cvrf логотип
SUSE-SU-2026:4017-1

Security update for postgresql15

8 дней назад
suse-cvrf логотип
SUSE-SU-2026:3944-1

Security update for postgresql14

12 дней назад
suse-cvrf логотип
SUSE-SU-2026:3941-1

Security update for postgresql14

12 дней назад
suse-cvrf логотип
SUSE-SU-2026:3940-1

Security update for postgresql15

12 дней назад
suse-cvrf логотип
SUSE-SU-2026:3793-1

Security update for postgresql14

21 день назад
suse-cvrf логотип
openSUSE-SU-2026:21702-1

Security update for postgresql17

16 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21701-1

Security update for postgresql16

16 дней назад
suse-cvrf логотип
SUSE-SU-2026:4016-1

Security update for postgresql17

8 дней назад
suse-cvrf логотип
SUSE-SU-2026:4013-1

Security update for postgresql17

8 дней назад
suse-cvrf логотип
SUSE-SU-2026:3963-1

Security update for postgresql16

12 дней назад

Уязвимостей на страницу