Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade postgresql15Upgrade postgresql17Upgrade postgresql18Upgrade postgresql16 | Aug 17, 2026 | Aug 13, 2026 |
| Debian | — | Upgrade postgresql-15Upgrade postgresql-17 | Aug 16, 2026 | Aug 16, 2026 |
| Freebsd | — | Upgrade postgresql18-serverUpgrade postgresql17-serverUpgrade postgresql16-serverUpgrade postgresql15-serverUpgrade postgresql14-server | Aug 17, 2026 | Aug 16, 2026 |
| Postgres | — | Upgrade to PostgreSQL version 16.15Upgrade to PostgreSQL version 15.19Upgrade to PostgreSQL version 17.11Upgrade to PostgreSQL version 14.24Upgrade to PostgreSQL version 18.5 | Aug 14, 2026 | Aug 13, 2026 |
| Ubuntu | — | Upgrade postgresql-18Upgrade postgresql-14Upgrade postgresql-16 | Aug 20, 2026 | Aug 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub