Improper Neutralization of Special Elements in Output Used by a Downstream Component in PostgreSQL - CVE-2026-18408
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements in pg_dump and related dump-generation tools when processing untrusted server-side data for restore in psql. A remote attacker can inject arbitrary code into a dump file to execute arbitrary code.
User interaction is required to restore the crafted dump with psql.
Affected software
Debian Linux
postgresql-17 (Debian package)
How to mitigate CVE-2026-18408
postgresql-17 (Debian package) - update to 17.11-0+deb13u1