CVE-CVE-2026-58225
Severity
UNKNOWN
CVSS Score
0.0
Description
SQL Injection vulnerability in elixir-ecto postgrex allows an attacker who can influence a LISTEN channel name to inject SQL into the reconnect replay query, causing a denial of service of the notification connection. Postgrex.Notifications sanitizes channel names with quote_channel/1, which doubles double quotes so the name is safe inside a double-quoted identifier. This protects the single-statement LISTEN and UNLISTEN paths. On every (re)connect, however, handle_connect/1 replays all registe...
PoCs for CVE-CVE-2026-58225
Learn-SecByte-CMS-CVE-Shell-to-Root-Privilege-Escalation-CTF...
General
0
sifatnotes
2026-09-28