PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands
Published Aug 13, 2026
8.1
HIGHCVSS 3.1
EPSS 0.36%
Description
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Affected products
- Vendor n/a Product PostgreSQL Defaultunaffected
- Version 0StatusaffectedConstraints<14.24
- Version 15StatusaffectedConstraints<15.19
- Version 16StatusaffectedConstraints<16.15
- Version 17StatusaffectedConstraints<17.11
- Version 18StatusaffectedConstraints<18.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | PostgreSQL | unaffected |
|
- ≥ 14.0 · < 14.24
- ≥ 15.0 · < 15.19
- ≥ 16.0 · < 16.15
- ≥ 17.0 · < 17.11
- ≥ 18.0 · < 18.5
No data.
Red Hat Enterprise Linux 10
postgresql18-0:18.6-1.el10_2
Fixed · RHSA-2026:67280
Red Hat Enterprise Linux 9
postgresql:16-9080020260907191505.rhel9
Fixed · RHSA-2026:67491
Red Hat Enterprise Linux 9
postgresql:18-9080020260914093252.rhel9
Fixed · RHSA-2026:67848
Red Hat Enterprise Linux 10
postgresql16
Affected
Red Hat Enterprise Linux 6
postgresql
Out of support scope
Red Hat Enterprise Linux 7
postgresql
Affected
Red Hat Enterprise Linux 8
postgresql:12/postgresql
Affected
Red Hat Enterprise Linux 8
postgresql:15/postgresql
Affected
Red Hat Enterprise Linux 8
postgresql:16/postgresql
Affected
Red Hat Enterprise Linux 9
postgresql
Affected
Red Hat Enterprise Linux 9
postgresql:15/postgresql
Affected
Red Hat Hardened Images
postgresql17
Not affected
Red Hat Hardened Images
postgresql18
Not affected
Self-service automation portal 2
ansible-automation-platform/bootc-automation-portal-rhel9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | postgresql18-0:18.6-1.el10_2 | Fixed | RHSA-2026:67280 |
| Red Hat Enterprise Linux 9 | postgresql:16-9080020260907191505.rhel9 | Fixed | RHSA-2026:67491 |
| Red Hat Enterprise Linux 9 | postgresql:18-9080020260914093252.rhel9 | Fixed | RHSA-2026:67848 |
| Red Hat Enterprise Linux 10 | postgresql16 | Affected | n/a |
| Red Hat Enterprise Linux 6 | postgresql | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | postgresql | Affected | n/a |
| Red Hat Enterprise Linux 8 | postgresql:12/postgresql | Affected | n/a |
| Red Hat Enterprise Linux 8 | postgresql:15/postgresql | Affected | n/a |
| Red Hat Enterprise Linux 8 | postgresql:16/postgresql | Affected | n/a |
| Red Hat Enterprise Linux 9 | postgresql | Affected | n/a |
| Red Hat Enterprise Linux 9 | postgresql:15/postgresql | Affected | n/a |
| Red Hat Hardened Images | postgresql17 | Not affected | n/a |
| Red Hat Hardened Images | postgresql18 | Not affected | n/a |
| Self-service automation portal 2 | ansible-automation-platform/bootc-automation-portal-rhel9 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This is an Important flaw in the PostgreSQL psql client that could lead to arbitrary command execution. When using `COPY FROM STDIN`, untrusted data can be processed as psql commands if an error injection causes the command to fail prematurely. Exploitation requires an attacker to control both the PostgreSQL server and the data rows, or to leverage a coincidental error, which significantly limits the attack surface in typical Red Hat deployments.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-6464 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2515306 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-57854 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-6464
- https://www.cve.org/CVERecord?id=CVE-2026-6464
- https://www.postgresql.org/support/security/CVE-2026-6464/ Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-6464 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2515306 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-57854 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-6464 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-6464 | ||
| https://www.postgresql.org/support/security/CVE-2026-6464/ | Vendor Advisory |
Change history (0)
No recorded changes yet.