HomeSecurityCritical PostgreSQL vulnerabilities allow Code Injection

Critical PostgreSQL vulnerabilities allow code injection

The PostgreSQL Global Development Group has issued urgent security updates for all supported versions to address three critical vulnerabilitiesthat could allow attackers to execute arbitrary code during database.

PostgreSQL Code Injection vulnerabilities

According to the company, PostgreSQL versions 13 through 17 are affected, with patches released for versions 17.6, 16.10, 15.14, 14.19 , and 13.22 .

In particular, two vulnerabilities pose particularly serious risks to organizations that rely on PostgreSQL backup and recovery processes. These vulnerabilities exploit pg_dump , a key tool for database backups

See also: Elastic EDR: Zero-day allows malware execution & BSOD

The most severe vulnerability, tracked as CVE-2025-8714 (CVSS score 8.8), allows malicious superusers on origin servers to inject arbitrary code, which is executed during restore. This attack method exploits the inclusion of untrusted data in pg_dump, allowing attackers to embed malicious psql meta-commands within backup files. When administrators restore these compromised copies via psql, the embedded commands are executed with the privileges of the client operating system account performing the restore. The vulnerability extends beyond the main pg_dump tool, affecting both pg_dumpall for cluster-wide backups and pg_restore when creating plain-format dumps. Security researchers Martin Rakhmanov, Matthieu Denais, and RyotaK discovered and reported this critical flaw to the PostgreSQL project.

Critical PostgreSQL vulnerabilities allow code injection

The second critical vulnerability, CVE-2025-8715 , exploits improper neutralization of newlines in object names in pg_dump output. Attackers can craft database objects with specially formatted names that contain embedded newline characters and psql meta-commands. During recovery, these malicious object names cause code execution on the client system running psql and potentially achieve SQL injection as superuser on the target database server. This flaw affects multiple PostgreSQL tools, including pg_dumpall , pg_restore , and pg_upgrade , expanding the potential attack surface to various database maintenance operations . Noah Misch discovered and reported the vulnerability.

See also: Hacker sells 15.8 million PayPal Email & Plaintext Passwords

Finally, PostgreSQL fixes the CVE-2025-8713 information disclosure vulnerability affecting PostgreSQL's optimizer statistics functionality. The vulnerability allows users to access sample data within views, partitions, and child tables that should be restricted by access control (ACLs) or row security policies.

Impact on businesses

  • Backup reliability: Backups are no longer 100% reliable unless they are verified.
  • Supply chain threat: A dump from a "trusted" source may be modified.
  • Review restore policies: Organizations need to re-examine how, by whom, and with what controls restores are performed.
Critical PostgreSQL vulnerabilities allow code injection

PostgreSQL Vulnerabilities : Recommended Protection Measures

  1. Immediate installation of updates (PostgreSQL 17.6, 16.10, 15.14, 14.19, 13.22).
  2. Authenticity check of dumps with hashing and signatures before restoration.
  3. Principle of least privilege – do not run pg_restore/psql with admin accounts unless necessary.
  4. Strict access controls for database management tools
  5. Restore environment isolation – restore first in sandbox, then transfer data to production.
  6. Monitoring & auditing – monitoring restore operations for suspicious commands/meta-commands.
  7. Training DBA teams to recognize signs of manipulation in object names or dumps.
  8. Application of the principle of least privilege during restoration work.

See also: Linux malware leak (linked to North Korean hackers)

These vulnerabilities indicate a shift in attack philosophy: cybercriminals no longer need to compromise online systems, they can plant traps in backups and wait for the organization to use them. This is doubly dangerous, because the moment of recovery usually occurs in a crisis situation (after ransomware, crash, etc.), so the IT team is already under pressure.

Source: cybersecuritynews.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS