Back

HIGH

SQL injection in ext-pgsql via E'...' backslash breakout

Published Jul 30, 2026

Description

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

Affected products

Remediation

Red Hat statement

The Red Hat Product Security team has assessed the severity of this vulnerability as Important. A remote attacker could exploit this flaw to inject malicious SQL commands into a connected PostgreSQL database, potentially exposing or manipulating sensitive data. However, only applications using PHP's older pg_insert(), pg_update(), pg_select(), or pg_delete() functions with unsanitized user input are at risk applications built on modern practices such as PDO, prepared statements, or parameterized queries are not affected. The vulnerability stems from improper handling of backslash characters in PHP's PostgreSQL extension, which can allow an attacker to break out of expected query boundaries and execute unintended SQL commands.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Metrics

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner php
Published Jul 30, 2026
Updated Jul 31, 2026
Reserved Jul 27, 2026
CISA Vulnrichment
Updated Jul 30, 2026
NVD
Status Analyzed
Modified Aug 5, 2026
Red Hat
Severity Important
Public date Jul 30, 2026