CVE-2025-8714: 18.3.3

Published Aug 14, 2025
·
Updated

Backport ‘Bump default ruby version to 3.2.9’Backport of “Use release-environment project id instead of canonical”Backport of ‘Danger to not warn in maintained stable branches’ to 18.3Backport of “Upgrade duo workflow client protocol version”Backport of “Filter out duplicate values from the variable options dropdown”18.3: Backport of ‘Fix security widget polling indefinitely when there are sboms’[18.3 backport] Remove CVE-2025-8714 commands from structure.sqlBackport 18.3: Do not trim deployment filename in geo secondary[Backport-18.3]Wiki search throws 500 error for some wiki content[18.3] Fix search admin page error when ES server returns forbiddenBackport of “Hide secrets manager settings behind feature flag instead of just the license” to 18.3Backport of Update the admin user for GET Release Environment QA tests[18.3] Backport: Resolve “Unable to fork project or create project if application wide lockduofeaturesenabled is true”Backport of Add Danger message to guide backport MR authors to reviewers and mergers (18.3)[Backport 18-3] Skip secret push protection for as-if-foss pipeline18.3: Backport of ‘Fix error when applying scanner suggestion’Backport of Ensure proper MCP URL OAuth Discovery for API/V4/MCPOptimize HandleMalformedStrings middleware for CPU and memoryBackport to 18.3 of Add job project claims to CI ID TokensBackport of Return success when status update target already matches[18.3] Fix flaky parallel design management uploads specBackport ‘Fix branches autocomplete paths in the merge request list app’ to 18-3Backport ‘Fix Linked file not being on top of the list’ to 18-3[18.3] Allow elastic client adapter to be setBackport of Use isUnsafeLink for xcode protocol18.3 Backport of ‘Resolve “Dependency list export with API silently fails license validation”’Backport: Fix registry matadata database password creationFall back to crehash if there are multiple TLS certificates

Other sources

PostgreSQL pgdump lets superuser of origin server execute arbitrary code in psql client

Microsoft

Untrusted data inclusion in pgdump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pgdumpall is also affected. pgrestore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.

NVD

Affected Software

7 affected componentsFixes available
PostgreSQL postgresql<17.6
PostgreSQL postgresql<16.10
PostgreSQL postgresql<15.14
PostgreSQL postgresql<14.19
PostgreSQL postgresql<13.22
Microsoft azl3 postgresql 16.9-1
Microsoft cbl2 postgresql 14.18-1

Event History

Aug 14, 2025
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·02:01 PM
DescriptionSeverityAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·07:03 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:03 AM
Affected Software
Updated
via Microsoft·07:03 AM
Affected Software
Updated
via Microsoft·07:03 AM
DescriptionSeverity
Apr 22, 2026
Data Sourced
via GitLab·08:55 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-8714?

CVE-2025-8714 has been classified with a high severity level due to its potential for arbitrary code execution.

2

How do I fix CVE-2025-8714?

To fix CVE-2025-8714, users should upgrade PostgreSQL to a version that is not affected, specifically versions 17.6 or later, or 16.10 or later, etc.

3

Who is affected by CVE-2025-8714?

CVE-2025-8714 affects PostgreSQL versions prior to 17.6, 16.10, 15.14, 14.19, and 13.22 for components like pg_dump, pg_dumpall, and pg_restore.

4

What impact does CVE-2025-8714 have?

The impact of CVE-2025-8714 allows a malicious superuser to execute arbitrary code on the client system during restore operations.

5

Is CVE-2025-8714 a remote exploit?

CVE-2025-8714 requires access to the server as a superuser, making it not a remote exploit in the typical sense.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203