Exposure of Sensitive Information Through Metadata Affecting libpq package, versions [,14.9)


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CONAN-LIBPQ-12008979
  • published19 Aug 2025
  • disclosed14 Aug 2025
  • creditDean Rasheed

Introduced: 14 Aug 2025

NewCVE-2025-8713  (opens in a new tab)
CWE-1230  (opens in a new tab)

How to fix?

Upgrade libpq to version 14.9 or higher.

Overview

Affected versions of this package are vulnerable to Exposure of Sensitive Information Through Metadata via optimizer statistics. An attacker can access sensitive sampled data by querying views, partitions, or child tables by crafting a leaky operator that bypasses view access control lists and bypasses row security policies in partitioning or table inheritance hierarchies.

CVSS Base Scores

version 4.0
version 3.1