postgres-github.git / summary / log / commit / refs

commit    d389415ffad509f0de1342e6ebbb5d5c62dbedef
Author:   Nathan Bossart <nathan@postgresql.org>
Commit:   Noah Misch <noah@leadboat.com>
Date:     Mon May 11 12:13:47 2026 +0000

    pg_createsubscriber: Obstruct SQL injection via subscription names.
    
    drop_existing_subscription() neglected to escape the subscription
    name when generating its query string.  To fix, use
    PQescapeIdentifier() to construct a properly escaped name, and use
    it in the ALTER SUBSCRIPTION and DROP SUBSCRIPTION commands.
    
    Reported-by: Yu Kunpeng <yu443940816@live.com>
    Author: Nathan Bossart <nathandbossart@gmail.com>
    Reviewed-by: Amit Kapila <amit.kapila16@gmail.com>
    Security: CVE-2026-6476
    Backpatch-through: 17

[parent: 6d6348f0329d]