CVE-2025-1094
PostgreSQL: libpq quoting functions allow SQL injection through invalidly encoded text
Technology
PostgreSQL
CVSS Score
8.1 / 10.0
Affected Versions
Before 17.3, 16.7, 15.11, 14.16 and 13.19 (12 and older not assessed)
Upstream Fix
17.3; 16.7; 15.11; 14.16; 13.19
Published
February 13, 2025
OSSeva Coverage
Fixed upstream
Description
PQescapeLiteral(), PQescapeIdentifier(), PQescapeString() and PQescapeStringConn() did not neutralize quoting syntax in text that fails encoding validation, so whoever provides the input could achieve SQL injection when an application uses the result to build input for psql. The command line utilities had a similar flaw when client_encoding is BIG5 and server_encoding is EUC_TW or MULE_INTERNAL. Scored 8.1 by PostgreSQL as the CNA. Fixed in 17.3, 16.7, 15.11, 14.16 and 13.19.
Is your PostgreSQL deployment affected?
If you're running Before 17.3, 16.7, 15.11, 14.16 and 13.19 (12 and older not assessed), you need this patch. Book a discovery call to get covered.