SQL Injection Vulnerability in Postgrex Affected by Elixir Ecto
CVE-2026-58225
Key Information:
- Vendor
Elixir-ecto
- Status
- Vendor
- CVE Published:
- 10 July 2026
Badges
What is CVE-2026-58225?
An SQL Injection vulnerability exists in Postgrex through Elixir's Ecto, allowing attackers to manipulate LISTEN channel names. This exploitation can lead to a denial of service, as malformed channel names cause the notification connection to break. While it does not permit arbitrary SQL execution, the flaw disrupts the notification system's ability to maintain subscriptions, resulting in silent data loss. Applications utilizing untrusted input for channel names are particularly vulnerable, impacting shared notification connections across multiple tenants.
Affected Version(s)
postgrex 0.16.0 < 0.22.3
postgrex 266b530faf9bde094e31e0e4ab851f933fadc0f5 < 795c6062f62c4394272ff4b89170688857b4f841
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
