CVE-2025-8714
published 2025-08-14CVE-2025-8714: Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the…
PriorityP354high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.74%
50.4th percentile
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | postgresql-13 | < postgresql-13 13.22-0+deb11u1 (bullseye) | postgresql-13 13.22-0+deb11u1 (bullseye) |
| debian | postgresql-15 | < postgresql-13 13.22-0+deb11u1 (bullseye) | postgresql-13 13.22-0+deb11u1 (bullseye) |
| debian | postgresql-17 | < postgresql-13 13.22-0+deb11u1 (bullseye) | postgresql-13 13.22-0+deb11u1 (bullseye) |
| msrc | azl3_postgresql_16.9-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_postgresql_14.18-1_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv4.9MEDIUM
vendor_msrc8.8HIGH
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
vendor_ubuntu3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2025-09-08·CVSS 3.1
CVE-2025-8713 [LOW] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: Several security issues were fixed in PostgreSQL.
Dean Rasheed discovered that PostgreSQL incorrectly handled access control
lists. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2025-8713)
Martin Rakhmanov, Matthieu Denais, and RyotaK discovered that the PostgreSQL
pg_dump utility allowed untrusted data inclusion. A malicious superuser
could use this issue to execute arbitrary code when a dump script is
reloaded. (CVE-2025-8714)
Noah Misch discovered that the PostgreSQL pg_dump utility incorrectly
filtered line breaks in object names. An attacker could create object names
that execute arbitrary SQL commands when a dump script is reloaded.
(CVE-2025-8715)
Instructions: This update uses a new upstream release,
Red Hat
postgresql: PostgreSQL code execution in restore operation
vendor_redhat·2025-08-14·CVSS 4.9
CVE-2025-8714 [MEDIUM] CWE-829 postgresql: PostgreSQL code execution in restore operation
postgresql: PostgreSQL code execution in restore operation
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
A flaw was found in PostgreSQL. This vulnerability allows a malicious superuser on a PostgreSQL server to inject arbitrary code into dump files created by pg_dump, pg_dumpall, and pg_restore, causing arbitrary code execution on the client machine when these dump files are res
Microsoft
PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client
vendor_msrc·2025-08-12·CVSS 8.8
CVE-2025-8714 [HIGH] CWE-829 PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client
PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
PostgreSQL: PostgreSQL
Customer Action Required: Yes
Remediation: CBL
Debian
CVE-2025-8714: postgresql-13 - Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser o...
vendor_debian·2025·CVSS 4.9
CVE-2025-8714 [MEDIUM] CVE-2025-8714: postgresql-13 - Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser o...
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
Scope: local
bullseye: resolved (fixed in 13.22-0+deb11u1)
OSV
postgresql-14, postgresql-16, postgresql-17 vulnerabilities
osv·2025-09-08·CVSS 3.1
CVE-2025-8713 [LOW] postgresql-14, postgresql-16, postgresql-17 vulnerabilities
postgresql-14, postgresql-16, postgresql-17 vulnerabilities
Dean Rasheed discovered that PostgreSQL incorrectly handled access control
lists. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2025-8713)
Martin Rakhmanov, Matthieu Denais, and RyotaK discovered that the PostgreSQL
pg_dump utility allowed untrusted data inclusion. A malicious superuser
could use this issue to execute arbitrary code when a dump script is
reloaded. (CVE-2025-8714)
Noah Misch discovered that the PostgreSQL pg_dump utility incorrectly
filtered line breaks in object names. An attacker could create object names
that execute arbitrary SQL commands when a dump script is reloaded.
(CVE-2025-8715)
GHSA
GHSA-6m5q-cc57-2mj6: Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time executio
ghsa_unreviewed·2025-08-14·CVSS 4.9
CVE-2025-8714 [MEDIUM] CWE-829 GHSA-6m5q-cc57-2mj6: Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time executio
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
OSV
CVE-2025-8714: Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time executio
osv·2025-08-14·CVSS 4.9
CVE-2025-8714 [MEDIUM] CVE-2025-8714: Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time executio
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-8714 postgresql17: PostgreSQL code execution in restore operation [fedora-42]
bugzilla·2025-08-14·CVSS 8.8
CVE-2025-8714 [HIGH] CVE-2025-8714 postgresql17: PostgreSQL code execution in restore operation [fedora-42]
CVE-2025-8714 postgresql17: PostgreSQL code execution in restore operation [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug r
Bugzilla
CVE-2025-8714 mingw-postgresql: PostgreSQL code execution in restore operation [fedora-42]
bugzilla·2025-08-14·CVSS 8.8
CVE-2025-8714 [HIGH] CVE-2025-8714 mingw-postgresql: PostgreSQL code execution in restore operation [fedora-42]
CVE-2025-8714 mingw-postgresql: PostgreSQL code execution in restore operation [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all b
Bugzilla
CVE-2025-8714 postgresql16: PostgreSQL code execution in restore operation [fedora-42]
bugzilla·2025-08-14·CVSS 8.8
CVE-2025-8714 [HIGH] CVE-2025-8714 postgresql16: PostgreSQL code execution in restore operation [fedora-42]
CVE-2025-8714 postgresql16: PostgreSQL code execution in restore operation [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
Filip: I noticed that F42 still provides psql 16.9 which is a big hassle for me because that version does not accept the `--restrict-key` parameter for `pg_dump. Anything I could do to speed this up?
2025-08-14
Published