Improper Neutralization of Special Elements in Output Used by a Downstream Component in PostgreSQL - CVE-2026-6464
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute psql commands.
The vulnerability exists due to untrusted data inclusion in psql COPY FROM STDIN handling when a COPY FROM STDIN or \\copy FROM STDIN command fails before the server indicates that it awaits input rows. A remote attacker can trigger an early failure so that in-line data rows are processed as psql commands to execute psql commands.
A complete attack requires control of both the server and the data rows, although an attacker controlling only the data rows might succeed if a coincidental error occurs.
Affected software
Debian Linux
postgresql-17 (Debian package)
How to mitigate CVE-2026-6464
postgresql-17 (Debian package) - update to 17.11-0+deb13u1