Database/Control plane, storage & DevOps
PostgreSQL (libpq): Improper quoting in PQescape*
CVSS 8.1CVE-2025-1094Control plane, storage & DevOpscurated
Impact
Improper quoting in PQescape* -> SQL injection, chainable to shell via psql \!
Who can reach it
Network (remote)
What to do
Control-plane: patch metadata/billing DB servers and all libpq clients
References
Related entries
- HPE Performance Cluster Manager (HPCM) GUI authentication bypass: Authentication bypass in the HPCM web GUICVE-2025-27086 · HPE Performance Cluster Manager (HPCM) GUI authentication bypassHigh
- HTCondor (IDToken authorization restrictions): The per-token authorization restrictions attached withCVE-2025-30093 · HTCondor (IDToken authorization restrictions)High
- ConnectWise ScreenConnect: ViewState code injectionCVE-2025-3935 · ConnectWise ScreenConnectHigh
- MinIO (service accounts / STS session policies): The session policy attached to a service account or STS credential isCVE-2025-62506 · MinIO (service accounts / STS session policies)High
- Apache CloudStack: MinIO policies survive bucket deletion, giving a former owner access to a new bucket of the same nameCVE-2025-66467 · Apache CloudStack (MinIO object store policy cleanup on bucket deletion)High
- N-able N-central: Incomplete patch for CVE-2026-18556CVE-2026-18577 · N-able N-centralHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.