CVE-2026-15741
PostgreSQL: SQL injection through EXTRACT() expression deparse
Technology
PostgreSQL
CVSS Score
8.8 / 10.0
Affected Versions
Before 18.6, 17.11, 16.15, 15.19 and 14.24 (supported versions only; 13 and older not assessed)
Upstream Fix
18.6; 17.11; 16.15; 15.19; 14.24
Published
August 13, 2026
OSSeva Coverage
Fixed upstream
Description
Deparsing EXTRACT() expressions allowed SQL injection, so an object owner could plant a hostile object definition that runs arbitrary SQL as a superuser when the expression is deparsed. That affects deparse consumers broadly, including pg_dump, psql commands such as \sf and similar code in other tools. Scored 8.8 by PostgreSQL as the CNA. Fixed in 18.6, 17.11, 16.15, 15.19 and 14.24.
Is your PostgreSQL deployment affected?
If you're running Before 18.6, 17.11, 16.15, 15.19 and 14.24 (supported versions only; 13 and older not assessed), you need this patch. Book a discovery call to get covered.