https://seclists.org/oss-sec/2025/q1/141: CVE-2025-1094: PostgSQL: Quoting APIs miss neutralizing quoting syntax in text that fails encoding validation, enabling psql SQL injection
Published Feb 16, 2025
·Updated
Affected Software
1 affected component
PostgreSQL Global Development Group PostgreSQL>=13.19<=17.3
Frequently Asked Questions
1
What is the severity of CVE-2025-1094?
CVE-2025-1094 has been classified as critical due to its potential for SQL injection attacks.
2
How do I fix CVE-2025-1094?
To fix CVE-2025-1094, upgrade PostgreSQL to version 17.3, 16.7, 15.1, 14.6, or 13.9 or later.
3
What systems are affected by CVE-2025-1094?
CVE-2025-1094 affects all supported versions of PostgreSQL prior to the specified fixed releases.
4
What is the impact of CVE-2025-1094?
The impact of CVE-2025-1094 allows attackers to execute arbitrary SQL commands via improper handling of quoted text.
5
When was CVE-2025-1094 published?
CVE-2025-1094 was published on February 16, 2025.