agora inbox for pgsql-bugs@postgresql.org  
help / color / mirror / Atom feed
From: PG Bug reporting form <noreply@postgresql.org>
To: pgsql-bugs@lists.postgresql.org
Cc: 1217816127@qq.com
Subject: BUG #19602: Vuln46: citext split_part silently returns NULL for a zero field position instead of raising core sp
Date: Mon, 03 Aug 2026 06:58:12 +0000
Message-ID: <19602-5ec4b4e30fa6f5f2@postgresql.org> (raw)

The following bug has been logged on the website:

Bug reference:      19602
Logged by:          Yuelin Wang
Email address:      1217816127@qq.com
PostgreSQL version: 19beta2
Operating system:   Linux (Ubuntu 24.04, x86_64)
Description:        

## Vuln46: citext split_part silently returns NULL for a zero field position
instead of raising core split_part's error

### Summary

citext.split_part(citext, citext, int) is implemented in SQL as an array
subscript expression (regexp_split_to_array(...))[$3] rather than by calling
pg_catalog.split_part. Postgres array subscripting silently returns NULL for
an out of range index such as 0, so citext's split_part diverges from core
split_part, which explicitly raises "field position must not be zero" for a
zero field argument.

CWE: CWE-1284. Severity: Low.

### PoC

```sql
CREATE EXTENSION citext;
SELECT split_part('abc~@~def~@~ghi'::citext, '~@~', 0) IS NULL AS is_null_0;
SELECT split_part('abc~@~def~@~ghi'::citext, '~@~', 0);
SELECT pg_catalog.split_part('abc~@~def~@~ghi', '~@~', 0);
```

### Result

Real captured output from the independent verification run:

```
CREATE EXTENSION
 is_null_0
-----------
 t
(1 row)

 split_part
------------
 
(1 row)

ERROR:  field position must not be zero
```

### Impact

An application that relies on split_part raising an error for a zero field
position to catch a programming or input validation bug will instead
silently receive NULL when operating on citext values, potentially masking
the underlying logic error rather than failing loudly.








view thread (2+ messages)  latest in thread

Message-ID: <19602-5ec4b4e30fa6f5f2@postgresql.org>
Permalink:  ../19602-5ec4b4e30fa6f5f2@postgresql.org/
Also on:    postgresql.org/message-id/19602-5ec4b4e30fa6f5f2@postgresql.org

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-bugs@postgresql.org
  Cc: noreply@postgresql.org, pgsql-bugs@lists.postgresql.org, 1217816127@qq.com
  Subject: Re: BUG #19602: Vuln46: citext split_part silently returns NULL for a zero field position instead of raising core sp
  In-Reply-To: <19602-5ec4b4e30fa6f5f2@postgresql.org>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox