Back to Vulnerability Directory
HIGHFixed upstream

CVE-2025-1094

PostgreSQL: libpq quoting functions allow SQL injection through invalidly encoded text

Technology

PostgreSQL

CVSS Score

8.1 / 10.0

Affected Versions

Before 17.3, 16.7, 15.11, 14.16 and 13.19 (12 and older not assessed)

Upstream Fix

17.3; 16.7; 15.11; 14.16; 13.19

Published

February 13, 2025

OSSeva Coverage

Fixed upstream

Description

PQescapeLiteral(), PQescapeIdentifier(), PQescapeString() and PQescapeStringConn() did not neutralize quoting syntax in text that fails encoding validation, so whoever provides the input could achieve SQL injection when an application uses the result to build input for psql. The command line utilities had a similar flaw when client_encoding is BIG5 and server_encoding is EUC_TW or MULE_INTERNAL. Scored 8.1 by PostgreSQL as the CNA. Fixed in 17.3, 16.7, 15.11, 14.16 and 13.19.

Upstream record: NVD · CVE.org

Is your PostgreSQL deployment affected?

If you're running Before 17.3, 16.7, 15.11, 14.16 and 13.19 (12 and older not assessed), you need this patch. Book a discovery call to get covered.