Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wqrjY-0000bL-0I for pgsql-bugs@arkaria.postgresql.org; Mon, 03 Aug 2026 12:25:32 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.96) (envelope-from ) id 1wqrCl-005xuA-0V for pgsql-bugs@arkaria.postgresql.org; Mon, 03 Aug 2026 11:51:39 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wqmdh-004WUx-0V for pgsql-bugs@lists.postgresql.org; Mon, 03 Aug 2026 06:59:09 +0000 Received: from mahout.postgresql.org ([2001:4800:3e1:1::227]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1wqmdd-00000001jX7-25Wl for pgsql-bugs@lists.postgresql.org; Mon, 03 Aug 2026 06:59:07 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=postgresql.org; s=20171124; h=Message-ID:Date:Reply-To:Cc:From:To:Subject: Content-Transfer-Encoding:MIME-Version:Content-Type:Sender:Content-ID: Content-Description:In-Reply-To:References; bh=AQ6pcRQ0AvCNkdmjokgY1os5Me799MdzMaeuyQ75q90=; b=JZsWjXlt2fsnA7Uk/ArGTDO0j6 6Ous8ajizH1E8YkQtDuq366FswFDEgdlTGU4PDFF5tmFkajY2qDRKzeHhKA5JFn+wSk24bA13Rd8v 1h7Xnj+s2+n6PshDnc7TGkMTeryJQxQxgpeKw3PCeXS2eDJR/nivrX1ql1mCZVmo2cxKybGKRKiYx ntSlM5kUZMARU2KCuH04KIoyZr42pofIo1+fReMpiDyanQdEz2csr9JW3zsvparw48AvtoWgskZ9k JB3k0XikjV4qHAAxNPwIITRYMpdGFyG4LcQSz3m409ntWqtOyHApGOM+7JmwR8KbbU/Paq6nqJnmJ EyI/0U9A==; Received: from wrigleys.postgresql.org ([2a02:16a8:dc51::60]) by mahout.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wqmdb-000rhu-1q for pgsql-bugs@lists.postgresql.org; Mon, 03 Aug 2026 06:59:04 +0000 Received: from localhost ([127.0.0.1] helo=wrigleys.postgresql.org) by wrigleys.postgresql.org with esmtp (Exim 4.98.2) (envelope-from ) id 1wqmdb-0000000CCQH-0k4e for pgsql-bugs@lists.postgresql.org; Mon, 03 Aug 2026 06:59:03 +0000 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Subject: BUG #19602: Vuln46: citext split_part silently returns NULL for a zero field position instead of raising core sp To: pgsql-bugs@lists.postgresql.org From: PG Bug reporting form Cc: 1217816127@qq.com Reply-To: 1217816127@qq.com, pgsql-bugs@lists.postgresql.org Date: Mon, 03 Aug 2026 06:58:12 +0000 Message-ID: <19602-5ec4b4e30fa6f5f2@postgresql.org> X-Auto-Response-Suppress: All Auto-Submitted: auto-generated List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk The following bug has been logged on the website: Bug reference: 19602 Logged by: Yuelin Wang Email address: 1217816127@qq.com PostgreSQL version: 19beta2 Operating system: Linux (Ubuntu 24.04, x86_64) Description: =20 ## Vuln46: citext split_part silently returns NULL for a zero field position instead of raising core split_part's error ### Summary citext.split_part(citext, citext, int) is implemented in SQL as an array subscript expression (regexp_split_to_array(...))[$3] rather than by calling pg_catalog.split_part. Postgres array subscripting silently returns NULL for an out of range index such as 0, so citext's split_part diverges from core split_part, which explicitly raises "field position must not be zero" for a zero field argument. CWE: CWE-1284. Severity: Low. ### PoC ```sql CREATE EXTENSION citext; SELECT split_part('abc~@~def~@~ghi'::citext, '~@~', 0) IS NULL AS is_null_0; SELECT split_part('abc~@~def~@~ghi'::citext, '~@~', 0); SELECT pg_catalog.split_part('abc~@~def~@~ghi', '~@~', 0); ``` ### Result Real captured output from the independent verification run: ``` CREATE EXTENSION is_null_0 ----------- t (1 row) split_part ------------ =20 (1 row) ERROR: field position must not be zero ``` ### Impact An application that relies on split_part raising an error for a zero field position to catch a programming or input validation bug will instead silently receive NULL when operating on citext values, potentially masking the underlying logic error rather than failing loudly.