CVE-2025-8714
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 0.74%
- CWE
- CWE-829
- Published
- 2025-08-14
- Last modified
- 2026-03-12
Affected products
- n/a PostgreSQL
- n/a PostgreSQL
- n/a PostgreSQL
- n/a PostgreSQL
- n/a PostgreSQL
Weakness type
Related vulnerabilities
- CVE-2026-0303 — Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File
- CVE-2026-79721 — Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer,...
- CVE-2026-86504 — In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev...
- CVE-2026-86169 — Axolotl through 0.18.0 Remote Code Execution via Multipack Patching
- CVE-2026-82525 — Exterro FTK Imager < 8.3 XXE via Report.xml XSLT Processing
- CVE-2026-58569 — Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability....
- CVE-2026-18252 — Inclusion of Functionality from Untrusted Control Sphere in GitLab
- CVE-2026-76139 — Acm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@master with full build credentials