postgres-github.git / summary / log / commit / refs
commit d389415ffad509f0de1342e6ebbb5d5c62dbedef
Author: Nathan Bossart <nathan@postgresql.org>
Commit: Noah Misch <noah@leadboat.com>
Date: Mon May 11 12:13:47 2026 +0000
pg_createsubscriber: Obstruct SQL injection via subscription names.
drop_existing_subscription() neglected to escape the subscription
name when generating its query string. To fix, use
PQescapeIdentifier() to construct a properly escaped name, and use
it in the ALTER SUBSCRIPTION and DROP SUBSCRIPTION commands.
Reported-by: Yu Kunpeng <yu443940816@live.com>
Author: Nathan Bossart <nathandbossart@gmail.com>
Reviewed-by: Amit Kapila <amit.kapila16@gmail.com>
Security: CVE-2026-6476
Backpatch-through: 17
[parent: 6d6348f0329d]