Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade postgresql16Upgrade postgresql18Upgrade postgresql17Upgrade postgresql15 | Aug 17, 2026 | Aug 13, 2026 |
| Debian | — | Upgrade postgresql-17Upgrade postgresql-15 | Aug 16, 2026 | Aug 16, 2026 |
| Freebsd | — | Upgrade postgresql14-serverUpgrade postgresql15-serverUpgrade postgresql17-serverUpgrade postgresql18-serverUpgrade postgresql16-server | Aug 17, 2026 | Aug 16, 2026 |
| Postgres | — | Upgrade to PostgreSQL version 18.5Upgrade to PostgreSQL version 16.15Upgrade to PostgreSQL version 17.11Upgrade to PostgreSQL version 15.19Upgrade to PostgreSQL version 14.24 | Aug 14, 2026 | Aug 13, 2026 |
| Ubuntu | — | Upgrade postgresql-14Upgrade postgresql-18Upgrade postgresql-16 | Aug 20, 2026 | Aug 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub