{"id":"CVE-2026-6638","year":2026,"sequence":6638,"component":"core server","score":3.7,"cvss_version":"3.0","vector":"AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N","first_published":"2026-05-14","source_url":"https://www.postgresql.org/support/security/CVE-2026-6638/","facts":{"affected":{"16":"16","17":"17","18":"18"},"affected_ranges":[{"from":"16","until":"16.14"},{"from":"17","until":"17.10"},{"from":"18","until":"18.4"}],"cna_url":"https://cveawg.mitre.org/api/cve/CVE-2026-6638","component":"core server","cvss_version":"3.0","description_en":"SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.","first_published":"2026-05-14","fixed":{"16":"16.14","17":"17.10","18":"18.4"},"id":"CVE-2026-6638","introduced":{},"published":{"16":"2026-05-14","17":"2026-05-14","18":"2026-05-14"},"score":3.7,"title":"PostgreSQL REFRESH PUBLICATION allows SQL injection via table name","url":"https://www.postgresql.org/support/security/CVE-2026-6638/","vector":"AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"zh-Hans","title":"PostgreSQL REFRESH PUBLICATION 可通过表名实施 SQL 注入","description":"PostgreSQL REFRESH PUBLICATION 可通过表名实施 SQL 注入","details":"PostgreSQL 逻辑复制的 ALTER SUBSCRIPTION ... REFRESH PUBLICATION 存在 SQL 注入， 订阅端表的创建者可使用订阅所配置的发布端凭据执行任意 SQL；攻击会在下次 REFRESH PUBLICATION 时生效。 在主版本 16、17 和 18 中，PostgreSQL 18.4、17.10 和 16.14 之前的小版本受此问题影响， PostgreSQL 16 之前的版本不受影响。","format":"markdown","provenance":{"identity":"immutable_cve_code","sources":[{"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"component":"core server","cve":"2026-6638","cvenumber":202606638,"description":"PostgreSQL REFRESH PUBLICATION 可通过表名实施 SQL 注入","details":"PostgreSQL 逻辑复制的 ALTER SUBSCRIPTION ... REFRESH PUBLICATION 存在 SQL 注入， 订阅端表的创建者可使用订阅所配置的发布端凭据执行任意 SQL；攻击会在下次 REFRESH PUBLICATION 时生效。 在主版本 16、17 和 18 中，PostgreSQL 18.4、17.10 和 16.14 之前的小版本受此问题影响， PostgreSQL 16 之前的版本不受影响。","detailslink":"","id":47,"legacyscore":"","newspost_id":3294,"public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N"},"source":"center","source_id":47,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"},{"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"component":"core server","cve":"2026-6638","cvenumber":202606638,"description":"PostgreSQL REFRESH PUBLICATION 可通过表名实施 SQL 注入","details":"PostgreSQL 逻辑复制的 ALTER SUBSCRIPTION ... REFRESH PUBLICATION 存在 SQL 注入， 订阅端表的创建者可使用订阅所配置的发布端凭据执行任意 SQL；攻击会在下次 REFRESH PUBLICATION 时生效。 在主版本 16、17 和 18 中，PostgreSQL 18.4、17.10 和 16.14 之前的小版本受此问题影响， PostgreSQL 16 之前的版本不受影响。","detailslink":"","id":47,"legacyscore":"","newspost_id":3294,"public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N"},"source":"pgweb","source_id":47,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"}]},"text_hash":"a8886cbefba1b86b3cd6c01ee2bd36f16f96e187dd0b73130944fa4981e51248"},"locales":["en","zh-Hans"],"fixes":[{"major":"16","fixed_version":"16.14","introduced":null,"published_date":"2026-05-14","facts":{"fixed":"16.14","introduced":null,"published":"2026-05-14"}},{"major":"17","fixed_version":"17.10","introduced":null,"published_date":"2026-05-14","facts":{"fixed":"17.10","introduced":null,"published":"2026-05-14"}},{"major":"18","fixed_version":"18.4","introduced":null,"published_date":"2026-05-14","facts":{"fixed":"18.4","introduced":null,"published":"2026-05-14"}}],"legacy":[{"source":"center","source_id":47,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":47,"cve":"2026-6638","public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N","details":"PostgreSQL 逻辑复制的 ALTER SUBSCRIPTION ... REFRESH PUBLICATION 存在 SQL 注入， 订阅端表的创建者可使用订阅所配置的发布端凭据执行任意 SQL；攻击会在下次 REFRESH PUBLICATION 时生效。 在主版本 16、17 和 18 中，PostgreSQL 18.4、17.10 和 16.14 之前的小版本受此问题影响， PostgreSQL 16 之前的版本不受影响。","component":"core server","cvenumber":202606638,"description":"PostgreSQL REFRESH PUBLICATION 可通过表名实施 SQL 注入","detailslink":"","legacyscore":"","newspost_id":3294},"fixes":[{"source_id":172,"source_version_id":31,"major":"18","fixed_minor":4,"raw":{"id":172,"patch_id":47,"version_id":31,"fixed_minor":4},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":173,"source_version_id":30,"major":"17","fixed_minor":10,"raw":{"id":173,"patch_id":47,"version_id":30,"fixed_minor":10},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":174,"source_version_id":29,"major":"16","fixed_minor":14,"raw":{"id":174,"patch_id":47,"version_id":29,"fixed_minor":14},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":15,"firstreldate":"2023-09-14"}}]},{"source":"pgweb","source_id":47,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":47,"cve":"2026-6638","public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N","details":"PostgreSQL 逻辑复制的 ALTER SUBSCRIPTION ... REFRESH PUBLICATION 存在 SQL 注入， 订阅端表的创建者可使用订阅所配置的发布端凭据执行任意 SQL；攻击会在下次 REFRESH PUBLICATION 时生效。 在主版本 16、17 和 18 中，PostgreSQL 18.4、17.10 和 16.14 之前的小版本受此问题影响， PostgreSQL 16 之前的版本不受影响。","component":"core server","cvenumber":202606638,"description":"PostgreSQL REFRESH PUBLICATION 可通过表名实施 SQL 注入","detailslink":"","legacyscore":"","newspost_id":3294},"fixes":[{"source_id":172,"source_version_id":31,"major":"18","fixed_minor":4,"raw":{"id":172,"patch_id":47,"version_id":31,"fixed_minor":4},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":173,"source_version_id":30,"major":"17","fixed_minor":10,"raw":{"id":173,"patch_id":47,"version_id":30,"fixed_minor":10},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":174,"source_version_id":29,"major":"16","fixed_minor":14,"raw":{"id":174,"patch_id":47,"version_id":29,"fixed_minor":14},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":15,"firstreldate":"2023-09-14"}}]}]}
