<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:34:25 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:1736 — Important: postgresql:13 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:1736</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: pg_repack, AlmaLinux:8: pgaudit, AlmaLinux:8: postgres-decoderbufs, AlmaLinux:8: postgresql, AlmaLinux:8: postgresql-contrib, AlmaLinux:8: postgresql-docs, AlmaLinux:8: postgresql-plperl, AlmaLinux:8: postgresql-plpython3, AlmaLinux:8: postgresql-pltcl, AlmaLinux:8: postgresql-server and 6 more&lt;/p&gt;
&lt;p&gt;PostgreSQL is an advanced object-relational database management system (DBMS).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* postgresql: PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation (CVE-2025-1094)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: pg_repack, AlmaLinux:8: pgaudit, AlmaLinux:8: postgres-decoderbufs, AlmaLinux:8: postgresql, AlmaLinux:8: postgresql-contrib, AlmaLinux:8: postgresql-docs, AlmaLinux:8: postgresql-plperl, AlmaLinux:8: postgresql-plpython3, AlmaLinux:8: postgresql-pltcl, AlmaLinux:8: postgresql-server and 6 more&lt;/p&gt;
&lt;p&gt;PostgreSQL is an advanced object-relational database management system (DBMS).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* postgresql: PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation (CVE-2025-1094)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:1736</guid>
    </item>
    <item>
      <title>bdu:2025-01601</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-01601</link>
      <description>bdu:2025-01601</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-01601</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-1094</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-1094</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: postgresql15, Alpaquita:stream: postgresql17&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: postgresql15, Alpaquita:stream: postgresql17&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-1094</guid>
    </item>
    <item>
      <title>BIT-postgresql-2025-1094 — PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation</title>
      <link>https://cve.radiocsirt.org/vuln/bit-postgresql-2025-1094</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: postgresql&lt;/p&gt;
&lt;p&gt;Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns.  Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal.  Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL.  Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: postgresql&lt;/p&gt;
&lt;p&gt;Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns.  Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal.  Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL.  Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-postgresql-2025-1094</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0130 — Une vulnérabilité a été découverte dans PostgreSQL. Elle permet à un attaquant de provoquer une exécution de code arbit…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0130</link>
      <description>certfr-2025-avi-0130</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0130</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-DU35799 — Security fixes in postgresql 16.8-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-du35799</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: postgresql&lt;/p&gt;
&lt;p&gt;Package postgresql version 16.8-r0 fixes 1 vulnerabilities: CVE-2025-1094&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: postgresql&lt;/p&gt;
&lt;p&gt;Package postgresql version 16.8-r0 fixes 1 vulnerabilities: CVE-2025-1094&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-du35799</guid>
    </item>
    <item>
      <title>EUVD-2026-222713</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-222713</link>
      <description>EUVD-2026-222713</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-222713</guid>
    </item>
    <item>
      <title>fkie_cve-2025-1094</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-1094</link>
      <description>&lt;p&gt;Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns.  Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal.  Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL.  Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns.  Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal.  Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL.  Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-1094</guid>
    </item>
    <item>
      <title>GHSA-mhw9-x46c-v6q4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mhw9-x46c-v6q4</link>
      <description>&lt;p&gt;Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns.  Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal.  Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL.  Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns.  Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal.  Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL.  Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mhw9-x46c-v6q4</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-1094 — PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-1094</link>
      <description>msrc_CVE-2025-1094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-1094</guid>
    </item>
    <item>
      <title>OESA-2025-1152 — postgresql security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1152</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: postgresql&lt;/p&gt;
&lt;p&gt;PostgreSQL is an advanced Object-Relational database management system (DBMS).
The base postgresql package contains the client programs that you&amp;amp;amp;apos;ll need to
access a PostgreSQL DBMS server, as well as HTML documentation for the whole
system.  These client programs can be located on the same machine as the
PostgreSQL server, or on a remote machine that accesses a PostgreSQL server
over a network connection.  The PostgreSQL server can be found in the
postgresql-server sub-package.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns.  Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal.  Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL.  Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.(CVE-2025-1094)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: postgresql&lt;/p&gt;
&lt;p&gt;PostgreSQL is an advanced Object-Relational database management system (DBMS).
The base postgresql package contains the client programs that you&amp;amp;amp;apos;ll need to
access a PostgreSQL DBMS server, as well as HTML documentation for the whole
system.  These client programs can be located on the same machine as the
PostgreSQL server, or on a remote machine that accesses a PostgreSQL server
over a network connection.  The PostgreSQL server can be found in the
postgresql-server sub-package.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns.  Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal.  Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL.  Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.(CVE-2025-1094)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1152</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:14805-1 — postgresql13-13.19-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14805-1</link>
      <description>&lt;p&gt;postgresql13-13.19-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;postgresql13-13.19-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:14805-1</guid>
    </item>
    <item>
      <title>RHSA-2025:1720 — Red Hat Security Advisory: libpq security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:1720</link>
      <description>&lt;p&gt;postgresql: PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;postgresql: PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:1720</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:0606-1 — Security update for postgresql13</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:0606-1</link>
      <description>&lt;p&gt;Security update for postgresql13&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for postgresql13&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:0606-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-1094</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-1094</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: postgresql-9.3, Ubuntu:Pro:16.04:LTS: postgresql-9.5, Ubuntu:Pro:18.04:LTS: postgresql-10, Ubuntu:20.04:LTS: postgresql-12, Ubuntu:22.04:LTS: postgresql-14, Ubuntu:24.04:LTS: postgresql-16&lt;/p&gt;
&lt;p&gt;Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns.  Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal.  Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL.  Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: postgresql-9.3, Ubuntu:Pro:16.04:LTS: postgresql-9.5, Ubuntu:Pro:18.04:LTS: postgresql-10, Ubuntu:20.04:LTS: postgresql-12, Ubuntu:22.04:LTS: postgresql-14, Ubuntu:24.04:LTS: postgresql-16&lt;/p&gt;
&lt;p&gt;Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns.  Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal.  Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL.  Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-1094</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0372 — PostgreSQL: Schwachstelle ermöglicht SQL Injection und Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0372</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in PostgreSQL ausnutzen, um eine SQL Injection durchzuführen und in der Folge beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in PostgreSQL ausnutzen, um eine SQL Injection durchzuführen und in der Folge beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0372</guid>
    </item>
  </channel>
</rss>
