CVE-2026-66838
- EPSS 0.24%
- Veröffentlicht 07.08.2026 12:20:02
- Zuletzt bearbeitet 17.08.2026 14:40:45
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex allows SQL Injection via the :comment option of Postgrex.stream/4. An attacker who can influence that value can close the comme...
CVE-2026-58225
- EPSS 0.16%
- Veröffentlicht 10.07.2026 11:16:36
- Zuletzt bearbeitet 10.07.2026 17:56:00
SQL Injection vulnerability in elixir-ecto postgrex allows an attacker who can influence a LISTEN channel name to inject SQL into the reconnect replay query, causing a denial of service of the notification connection. Postgrex.Notifications sanitize...
CVE-2026-32687
- EPSS 0.2%
- Veröffentlicht 12.05.2026 14:18:07
- Zuletzt bearbeitet 24.07.2026 15:17:16
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex ('Elixir.Postgrex.Notifications' module) allows SQL Injection. The channel argument passed to 'Elixir.Postgrex.Notifications':...