{"id":"CVE-2025-8715","year":2025,"sequence":8715,"component":"core server","score":8.8,"cvss_version":"3.0","vector":"AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","first_published":"2025-08-14","source_url":"https://www.postgresql.org/support/security/CVE-2025-8715/","facts":{"affected":{"13":"13","14":"14","15":"15","16":"16","17":"17"},"affected_ranges":[{"from":"11.20","until":"13.22"},{"from":"14","until":"14.19"},{"from":"15","until":"15.14"},{"from":"16","until":"16.10"},{"from":"17","until":"17.6"}],"cna_url":"https://cveawg.mitre.org/api/cve/CVE-2025-8715","component":"core server","cvss_version":"3.0","description_en":"Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks can achieve SQL injection as a superuser of the restore target server. pg_dumpall, pg_restore, and pg_upgrade are also affected. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. Versions before 11.20 are unaffected. CVE-2012-0868 had fixed this class of problem, but version 11.20 reintroduced it.","first_published":"2025-08-14","fixed":{"13":"13.22","14":"14.19","15":"15.14","16":"16.10","17":"17.6"},"id":"CVE-2025-8715","introduced":{},"published":{"13":"2025-08-14","14":"2025-08-14","15":"2025-08-14","16":"2025-08-14","17":"2025-08-14"},"score":8.8,"title":"PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server","url":"https://www.postgresql.org/support/security/CVE-2025-8715/","vector":"AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"en","title":"PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server","description":"Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks can achieve SQL injection as a superuser of the restore target server. pg_dumpall, pg_restore, and pg_upgrade are also affected. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. Versions before 11.20 are unaffected. CVE-2012-0868 had fixed this class of problem, but version 11.20 reintroduced it.","details":null,"format":"plain","provenance":{"fetched_at":"2026-09-26T10:56:06+00:00","path":"compare/security.json","root":"source-data","sha256":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_archive_sha256":"8d8ad63581e1d27b3a0f995ded3feb81c265e38b2ac652eb22f022f52c2240ec","source_revision":"004bc292ee31c11f9a41ab007e9d8116bce29a71","source_url":"https://www.postgresql.org/support/security/"},"text_hash":"e056724da6a095ae2795c086d3e9ed5b86660e900cac593b646cd4f7d13838c0"},"locales":["en","zh-Hans"],"fixes":[{"major":"13","fixed_version":"13.22","introduced":null,"published_date":"2025-08-14","facts":{"fixed":"13.22","introduced":null,"published":"2025-08-14"}},{"major":"14","fixed_version":"14.19","introduced":null,"published_date":"2025-08-14","facts":{"fixed":"14.19","introduced":null,"published":"2025-08-14"}},{"major":"15","fixed_version":"15.14","introduced":null,"published_date":"2025-08-14","facts":{"fixed":"15.14","introduced":null,"published":"2025-08-14"}},{"major":"16","fixed_version":"16.10","introduced":null,"published_date":"2025-08-14","facts":{"fixed":"16.10","introduced":null,"published":"2025-08-14"}},{"major":"17","fixed_version":"17.6","introduced":null,"published_date":"2025-08-14","facts":{"fixed":"17.6","introduced":null,"published":"2025-08-14"}}],"legacy":[{"source":"center","source_id":8,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":8,"cve":"2025-8715","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","details":null,"component":"core server","cvenumber":202508715,"description":"PostgreSQL pg_dump 中对象名包含换行符时，可在 psql 客户端和恢复目标服务器上执行任意代码","detailslink":"https://access.redhat.com/security/cve/CVE-2025-8715","legacyscore":"","newspost_id":null},"fixes":[{"source_id":32,"source_version_id":30,"major":"17","fixed_minor":6,"raw":{"id":32,"patch_id":8,"version_id":30,"fixed_minor":6},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":33,"source_version_id":29,"major":"16","fixed_minor":10,"raw":{"id":33,"patch_id":8,"version_id":29,"fixed_minor":10},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":34,"source_version_id":28,"major":"15","fixed_minor":14,"raw":{"id":34,"patch_id":8,"version_id":28,"fixed_minor":14},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":35,"source_version_id":27,"major":"14","fixed_minor":19,"raw":{"id":35,"patch_id":8,"version_id":27,"fixed_minor":19},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":24,"firstreldate":"2021-09-30"}},{"source_id":188,"source_version_id":26,"major":"13","fixed_minor":22,"raw":{"id":188,"patch_id":8,"version_id":26,"fixed_minor":22},"version_raw":{"id":26,"tree":13.0,"current":false,"docsgit":"","eoldate":"2025-11-13","reldate":"2025-11-13","testing":0,"supported":false,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":23,"firstreldate":"2020-09-24"}}]},{"source":"pgweb","source_id":8,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":8,"cve":"2025-8715","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","details":null,"component":"core server","cvenumber":202508715,"description":"PostgreSQL pg_dump 中对象名包含换行符时，可在 psql 客户端和恢复目标服务器上执行任意代码","detailslink":"https://access.redhat.com/security/cve/CVE-2025-8715","legacyscore":"","newspost_id":null},"fixes":[{"source_id":32,"source_version_id":30,"major":"17","fixed_minor":6,"raw":{"id":32,"patch_id":8,"version_id":30,"fixed_minor":6},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":33,"source_version_id":29,"major":"16","fixed_minor":10,"raw":{"id":33,"patch_id":8,"version_id":29,"fixed_minor":10},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":34,"source_version_id":28,"major":"15","fixed_minor":14,"raw":{"id":34,"patch_id":8,"version_id":28,"fixed_minor":14},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":35,"source_version_id":27,"major":"14","fixed_minor":19,"raw":{"id":35,"patch_id":8,"version_id":27,"fixed_minor":19},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":24,"firstreldate":"2021-09-30"}},{"source_id":188,"source_version_id":26,"major":"13","fixed_minor":22,"raw":{"id":188,"patch_id":8,"version_id":26,"fixed_minor":22},"version_raw":{"id":26,"tree":13.0,"current":false,"docsgit":"","eoldate":"2025-11-13","reldate":"2025-11-13","testing":0,"supported":false,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":23,"firstreldate":"2020-09-24"}}]}]}
