SQL injection in ext-pgsql via E'...' backslash breakout
Published Jul 30, 2026
8.1
HIGHCVSS 4.0
EPSS 0.33%
Description
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
Affected products
-
- Version 8.2.*StatusaffectedConstraints<8.2.33
- Version 8.3.*StatusaffectedConstraints<8.3.33
- Version 8.4.*StatusaffectedConstraints<8.4.24
- Version 8.5.*StatusaffectedConstraints<8.5.9
- Version
No data.
Red Hat Enterprise Linux 10
php-0:8.3.33-1.el10_2
Fixed · RHSA-2026:62614
Red Hat Enterprise Linux 10
php8.4-0:8.4.24-1.el10_2
Fixed · RHSA-2026:56969
Red Hat Enterprise Linux 8
php:7.4-8100020260805070257.f7998665
Fixed · RHSA-2026:62334
Red Hat Enterprise Linux 8
php:8.2-8100020260806050858.f7998665
Fixed · RHSA-2026:57574
Red Hat Enterprise Linux 9
php-0:8.0.30-8.el9_8
Fixed · RHSA-2026:61259
Red Hat Enterprise Linux 9
php:8.2-9080020260806120914.9
Fixed · RHSA-2026:61903
Red Hat Enterprise Linux 9
php:8.3-9080020260806131732.9
Fixed · RHSA-2026:57539
Red Hat Hardened Images
php-main-8.5.9-1.hum1
Fixed · RHSA-2026:47200
Red Hat Enterprise Linux 6
php
Out of support scope
Red Hat Enterprise Linux 7
php
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | php-0:8.3.33-1.el10_2 | Fixed | RHSA-2026:62614 |
| Red Hat Enterprise Linux 10 | php8.4-0:8.4.24-1.el10_2 | Fixed | RHSA-2026:56969 |
| Red Hat Enterprise Linux 8 | php:7.4-8100020260805070257.f7998665 | Fixed | RHSA-2026:62334 |
| Red Hat Enterprise Linux 8 | php:8.2-8100020260806050858.f7998665 | Fixed | RHSA-2026:57574 |
| Red Hat Enterprise Linux 9 | php-0:8.0.30-8.el9_8 | Fixed | RHSA-2026:61259 |
| Red Hat Enterprise Linux 9 | php:8.2-9080020260806120914.9 | Fixed | RHSA-2026:61903 |
| Red Hat Enterprise Linux 9 | php:8.3-9080020260806131732.9 | Fixed | RHSA-2026:57539 |
| Red Hat Hardened Images | php-main-8.5.9-1.hum1 | Fixed | RHSA-2026:47200 |
| Red Hat Enterprise Linux 6 | php | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | php | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The Red Hat Product Security team has assessed the severity of this vulnerability as Important. A remote attacker could exploit this flaw to inject malicious SQL commands into a connected PostgreSQL database, potentially exposing or manipulating sensitive data. However, only applications using PHP's older pg_insert(), pg_update(), pg_select(), or pg_delete() functions with unsanitized user input are at risk applications built on modern practices such as PDO, prepared statements, or parameterized queries are not affected. The vulnerability stems from improper handling of backslash characters in PHP's PostgreSQL extension, which can allow an attacker to break out of expected query boundaries and execute unintended SQL commands.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:Y/R:U
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Jul 30, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jul–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.33% (0.00330) | 23.75th | v5 (v2026.06.15) |
| Jul 31, 2026 | 0.39% (0.00386) | 31.34th | v5 (v2026.06.15) |
References (5)
- https://access.redhat.com/security/cve/CVE-2026-17543 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2509254 Issue Tracking
- https://github.com/php/php-src/security/advisories/GHSA-7qpv-r5mr-78m4 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-17543
- https://www.cve.org/CVERecord?id=CVE-2026-17543
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-17543 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2509254 | Issue Tracking | |
| https://github.com/php/php-src/security/advisories/GHSA-7qpv-r5mr-78m4 | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-17543 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-17543 |
Change history (0)
No recorded changes yet.