<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:27:25.257058+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:1736</id>
    <title>ALSA-2025:1736 — Important: postgresql:13 security update</title>
    <updated>2026-10-02T15:27:26.279229+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: pg_repack, AlmaLinux:8: pgaudit, AlmaLinux:8: postgres-decoderbufs, AlmaLinux:8: postgresql, AlmaLinux:8: postgresql-contrib, AlmaLinux:8: postgresql-docs, AlmaLinux:8: postgresql-plperl, AlmaLinux:8: postgresql-plpython3, AlmaLinux:8: postgresql-pltcl, AlmaLinux:8: postgresql-server and 6 more</p>
<p>PostgreSQL is an advanced object-relational database management system (DBMS).</p>
<p>Security Fix(es):</p>
<p>* postgresql: PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation (CVE-2025-1094)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:1736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-01601</id>
    <title>bdu:2025-01601</title>
    <updated>2026-10-02T15:27:26.279380+00:00</updated>
    <content>bdu:2025-01601</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-01601"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-1094</id>
    <title>BELL-CVE-2025-1094</title>
    <updated>2026-10-02T15:27:26.279399+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: postgresql15, Alpaquita:stream: postgresql17</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-1094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-postgresql-2025-1094</id>
    <title>BIT-postgresql-2025-1094 — PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation</title>
    <updated>2026-10-02T15:27:26.279419+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: postgresql</p>
<p>Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns.  Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal.  Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL.  Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-postgresql-2025-1094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0130</id>
    <title>certfr-2025-avi-0130 — Une vulnérabilité a été découverte dans PostgreSQL. Elle permet à un attaquant de provoquer une exécution de code arbit…</title>
    <updated>2026-10-02T15:27:26.279443+00:00</updated>
    <content>certfr-2025-avi-0130</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0130"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-du35799</id>
    <title>Withdrawn: CLEANSTART-2026-DU35799 — Security fixes in postgresql 16.8-r0</title>
    <updated>2026-10-02T15:27:26.279459+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: postgresql</p>
<p>Package postgresql version 16.8-r0 fixes 1 vulnerabilities: CVE-2025-1094</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-du35799"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-222713</id>
    <title>EUVD-2026-222713</title>
    <updated>2026-10-02T15:27:26.279478+00:00</updated>
    <content>EUVD-2026-222713</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-222713"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-1094</id>
    <title>fkie_cve-2025-1094</title>
    <updated>2026-10-02T15:27:26.279489+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns.  Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal.  Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL.  Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-1094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mhw9-x46c-v6q4</id>
    <title>GHSA-mhw9-x46c-v6q4</title>
    <updated>2026-10-02T15:27:26.279512+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns.  Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal.  Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL.  Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mhw9-x46c-v6q4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-1094</id>
    <title>msrc_CVE-2025-1094 — PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation</title>
    <updated>2026-10-02T15:27:26.279530+00:00</updated>
    <content>msrc_CVE-2025-1094</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-1094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1152</id>
    <title>OESA-2025-1152 — postgresql security update</title>
    <updated>2026-10-02T15:27:26.279546+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: postgresql</p>
<p>PostgreSQL is an advanced Object-Relational database management system (DBMS).
The base postgresql package contains the client programs that you&amp;amp;apos;ll need to
access a PostgreSQL DBMS server, as well as HTML documentation for the whole
system.  These client programs can be located on the same machine as the
PostgreSQL server, or on a remote machine that accesses a PostgreSQL server
over a network connection.  The PostgreSQL server can be found in the
postgresql-server sub-package.

Security Fix(es):</p>
<p>Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns.  Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal.  Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL.  Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.(CVE-2025-1094)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1152"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14805-1</id>
    <title>openSUSE-SU-2025:14805-1 — postgresql13-13.19-1.1 on GA media</title>
    <updated>2026-10-02T15:27:26.279576+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>postgresql13-13.19-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:14805-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:1720</id>
    <title>RHSA-2025:1720 — Red Hat Security Advisory: libpq security update</title>
    <updated>2026-10-02T15:27:26.279592+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>postgresql: PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:1720"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:0606-1</id>
    <title>SUSE-SU-2025:0606-1 — Security update for postgresql13</title>
    <updated>2026-10-02T15:27:26.279607+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for postgresql13</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:0606-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-1094</id>
    <title>UBUNTU-CVE-2025-1094</title>
    <updated>2026-10-02T15:27:26.279620+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: postgresql-9.3, Ubuntu:Pro:16.04:LTS: postgresql-9.5, Ubuntu:Pro:18.04:LTS: postgresql-10, Ubuntu:20.04:LTS: postgresql-12, Ubuntu:22.04:LTS: postgresql-14, Ubuntu:24.04:LTS: postgresql-16</p>
<p>Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns.  Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal.  Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL.  Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-1094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0372</id>
    <title>WID-SEC-W-2025-0372 — PostgreSQL: Schwachstelle ermöglicht SQL Injection und Codeausführung</title>
    <updated>2026-10-02T15:27:26.279650+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in PostgreSQL ausnutzen, um eine SQL Injection durchzuführen und in der Folge beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0372"/>
  </entry>
</feed>
