Unsafe Dependency Resolution Affecting postgresql package, versions [14.0,14.24)[15.0,15.19)[16.0,16.15)[17.0,17.11)[18.0,18.5)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.36% (29th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-POSTGRESQL-19427841
  • published29 Aug 2026
  • disclosed13 Aug 2026
  • creditUnknown

Introduced: 13 Aug 2026

NewCVE-2026-18408  (opens in a new tab)
CWE-829  (opens in a new tab)

How to fix?

Upgrade postgresql to version 14.24, 15.19, 16.15, 17.11, 18.5 or higher.

Overview

Affected versions of this package are vulnerable to Unsafe Dependency Resolution via the \unrestrict meta-command input expansion in the restore process. An attacker can execute arbitrary code as the client operating system account by injecting malicious input from a compromised origin server during the restoration of a database dump using psql. This is only exploitable if the attacker has superuser privileges on the origin server and the dump is restored using methods that involve psql.

Workaround

This vulnerability can be mitigated by using "pg_restore --dbname" instead of restore methods that involve "psql".

CVSS Base Scores

version 4.0
version 3.1