Logo
vulnerabilityCVE-2026-6638
Name
CVE-2026-6638
Source
NVD ( link)Debian ( link)
Description
SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
postgresql
Exploitable

Vulnerability Ratings#


3.7
CVSSv31
8.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
17.10
Not Affected
buildroot
master
18.4
Not Affected
openwrt
master
18.4-r1
Not Affected
yocto
kirkstone
14.22
Not Affected
yocto
master
17.10
Not Affected
yocto
scarthgap
16.14
Not Affected