Back

HIGH

PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands

Published Aug 13, 2026

Description

Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Affected products

Remediation

Red Hat statement

This is an Important flaw in the PostgreSQL psql client that could lead to arbitrary command execution. When using `COPY FROM STDIN`, untrusted data can be processed as psql commands if an error injection causes the command to fail prematurely. Exploitation requires an attacker to control both the PostgreSQL server and the data rows, or to leverage a coincidental error, which significantly limits the attack surface in typical Red Hat deployments.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner PostgreSQL
Published Aug 13, 2026
Updated Aug 29, 2026
Reserved Apr 17, 2026
CISA Vulnrichment
Updated Aug 13, 2026
NVD
Status Modified
Modified Aug 29, 2026
Red Hat
Severity Important
Public date Aug 13, 2026
ENISA EUVD
Assigner PostgreSQL
Published Aug 13, 2026
Updated Aug 29, 2026
Exploited since n/a
EUVD-2026-57854