Back to Vulnerability Directory
HIGHFixed upstream

CVE-2025-8714

PostgreSQL: pg_dump lets a superuser of the origin server inject code that runs at restore

Technology

PostgreSQL

CVSS Score

8.8 / 10.0

Affected Versions

Before 17.6, 16.10, 15.14, 14.19 and 13.22 (12 and older not assessed)

Upstream Fix

17.6; 16.10; 15.14; 14.19; 13.22

Published

August 14, 2025

OSSeva Coverage

Fixed upstream

Description

pg_dump included untrusted data in its output, so a malicious superuser of the origin server could inject psql meta-commands that run arbitrary code as the client operating system account restoring the dump with psql. pg_dumpall is also affected, and pg_restore when it generates a plain-format dump. Scored 8.8 by PostgreSQL as the CNA. Fixed in 17.6, 16.10, 15.14, 14.19 and 13.22.

Upstream record: NVD · CVE.org

Is your PostgreSQL deployment affected?

If you're running Before 17.6, 16.10, 15.14, 14.19 and 13.22 (12 and older not assessed), you need this patch. Book a discovery call to get covered.