CVE-2026-15741 | PostgreSQL up to 18.4 Deparse EXTRACT sql injection
A vulnerability was found in PostgreSQL up to 14.23/15.18/16.14/17.10/18.4. It has been declared as critical. This affects the function EXTRACT of the component Deparse. The manipulation results in sql injection.
This vulnerability is known as CVE-2026-15741. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More