Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-15741

PostgreSQL: SQL injection through EXTRACT() expression deparse

Technology

PostgreSQL

CVSS Score

8.8 / 10.0

Affected Versions

Before 18.6, 17.11, 16.15, 15.19 and 14.24 (supported versions only; 13 and older not assessed)

Upstream Fix

18.6; 17.11; 16.15; 15.19; 14.24

Published

August 13, 2026

OSSeva Coverage

Fixed upstream

Description

Deparsing EXTRACT() expressions allowed SQL injection, so an object owner could plant a hostile object definition that runs arbitrary SQL as a superuser when the expression is deparsed. That affects deparse consumers broadly, including pg_dump, psql commands such as \sf and similar code in other tools. Scored 8.8 by PostgreSQL as the CNA. Fixed in 18.6, 17.11, 16.15, 15.19 and 14.24.

Upstream record: NVD · CVE.org

Is your PostgreSQL deployment affected?

If you're running Before 18.6, 17.11, 16.15, 15.19 and 14.24 (supported versions only; 13 and older not assessed), you need this patch. Book a discovery call to get covered.