agora inbox for pgsql-bugs@postgresql.org  
help / color / mirror / Atom feed
From: PG Bug reporting form <noreply@postgresql.org>
To: pgsql-bugs@lists.postgresql.org
Cc: imchifan@163.com
Subject: BUG #19702: decode() accepts Base64 payload after terminal padding
Date: Sat, 19 Sep 2026 11:15:48 +0000
Message-ID: <19702-9ed4a131fcfadb9d@postgresql.org> (raw)

The following bug has been logged on the website:

Bug reference:      19702
Logged by:          Qifan Liu
Email address:      imchifan@163.com
PostgreSQL version: 18.6
Operating system:   Linux/amd64
Description:        

decode() accepts Base64 alphabet characters after terminal '=' padding and
incorporates them into the decoded bytea value. Once terminal padding
completes a Base64 value, only ignorable whitespace may follow. Applications
relying on decode() to validate Base64 input may consequently process
malformed input as valid data.

Steps to reproduce
------------------
Run the following with psql:

\set ON_ERROR_STOP on
SELECT encode(decode('YQ==Yg==', 'base64'), 'hex') AS decoded_hex;
SELECT encode(decode('YQ==AAAA', 'base64'), 'hex') AS
decoded_hex_after_padding;

Actual result
-------------
 decoded_hex
-------------
 6162
(1 row)

 decoded_hex_after_padding
---------------------------
 6100
(1 row)

Expected result
---------------
Both decode() calls should reject their input with SQLSTATE 22023 because
Base64 alphabet characters occur after terminal '=' padding. They should not
silently decode the trailing payload.

Additional information
----------------------
The issue was reproduced on PostgreSQL 20devel, PostgreSQL 18.6, and
PostgreSQL 17.11.








view thread (2+ messages)  latest in thread

Message-ID: <19702-9ed4a131fcfadb9d@postgresql.org>
Permalink:  ../19702-9ed4a131fcfadb9d@postgresql.org/
Also on:    postgresql.org/message-id/19702-9ed4a131fcfadb9d@postgresql.org

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-bugs@postgresql.org
  Cc: noreply@postgresql.org, pgsql-bugs@lists.postgresql.org, imchifan@163.com
  Subject: Re: BUG #19702: decode() accepts Base64 payload after terminal padding
  In-Reply-To: <19702-9ed4a131fcfadb9d@postgresql.org>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox