CVE-2026-6638: PostgreSQL
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.
Affected products
- PostgreSQL PostgreSQL: from 16.0, before 16.14 (fixed in 16.14); from 17.0, before 17.10 (fixed in 17.10); from 18.0, before 18.4 (fixed in 18.4)
Published 2026-05-14. Last modified 2026-06-17.