SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.

Project Subscriptions

No data.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6270-1 postgresql-17 security update
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 14 May 2026 13:30:00 +0000

Type Values Removed Values Added
Description SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.
Title PostgreSQL REFRESH PUBLICATION allows SQL injection via table name
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: PostgreSQL

Published:

Updated: 2026-05-14T13:00:15.848Z

Reserved: 2026-04-19T19:58:21.650Z

Link: CVE-2026-6638

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-14T14:16:25.937

Modified: 2026-05-14T14:16:25.937

Link: CVE-2026-6638

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses