<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Postgresql — PoC Archive</title><link>https://poc.intelseclab.com/tags/postgresql/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 06 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/postgresql/index.xml" rel="self" type="application/rss+xml"/><item><title>pgAdmin 4 Restore Feature Regex-Bypass Command Injection RCE (CVE-2025-13780)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13780-pgadmin4-regex-bypass-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13780-pgadmin4-regex-bypass-rce/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2025-13780. Status: Weaponized. Affects: pgAdmin 4. Tags: pgadmin4, postgresql, regex-bypass, command-injection, psql-meta-command, utf8-bom, crlf-injection, rce, python, cwe-77, cwe-88.</description><category>web</category><category>Critical</category><category>pgadmin4</category><category>postgresql</category><category>regex-bypass</category><category>command-injection</category><category>psql-meta-command</category><category>utf8-bom</category><category>crlf-injection</category><category>rce</category><category>python</category><category>cwe-77</category><category>cwe-88</category></item><item><title>pgAdmin 4 Query Tool Authenticated eval() RCE (CVE-2025-2945)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-2945-pgadmin-eval-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-2945-pgadmin-eval-rce/</guid><description>Critical severity (CVSS 9.9) — web · CVE-2025-2945. Status: Weaponized. Affects: pgAdmin 4 (web-based PostgreSQL administration tool). Tags: pgadmin, postgresql, rce, eval-injection, code-injection, cwe-95, python, authenticated, sqleditor.</description><category>web</category><category>Critical</category><category>pgadmin</category><category>postgresql</category><category>rce</category><category>eval-injection</category><category>code-injection</category><category>cwe-95</category><category>python</category><category>authenticated</category><category>sqleditor</category></item><item><title>PostgreSQL pgcrypto PGP Heap Overflow to Superuser Escalation — CVE-2026-2005</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-2005-postgresql-pgcrypto-heapoverflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-2005-postgresql-pgcrypto-heapoverflow/</guid><description>Critical severity — binary · CVE-2026-2005. Status: PoC. Affects: PostgreSQL pgcrypto extension (PGP session-key parsing). Tags: postgresql, pgcrypto, heap-overflow, aslr-bypass, privilege-escalation, pgp, memory-corruption.</description><category>binary</category><category>Critical</category><category>postgresql</category><category>pgcrypto</category><category>heap-overflow</category><category>aslr-bypass</category><category>privilege-escalation</category><category>pgp</category><category>memory-corruption</category></item><item><title>PgBouncer SASL Length Field Integer Overflow Crash — CVE-2026-6664</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-6664-pgbouncer-integer-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-6664-pgbouncer-integer-overflow/</guid><description>High severity — network · CVE-2026-6664. Status: PoC. Affects: PgBouncer (PostgreSQL connection pooler). Tags: pgbouncer, postgresql, integer-overflow, sasl, scram, dos, cwe-190.</description><category>network</category><category>High</category><category>pgbouncer</category><category>postgresql</category><category>integer-overflow</category><category>sasl</category><category>scram</category><category>dos</category><category>cwe-190</category></item><item><title>Percona PMM Authenticated RCE via PostgreSQL COPY TO PROGRAM (CVE-2026-25212)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25212-percona-pmm-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25212-percona-pmm-rce/</guid><description>Critical severity (CVSS 9.9) — web · CVE-2026-25212. Status: PoC. Affects: Percona Monitoring and Management (PMM). Tags: rce, percona-pmm, postgresql, copy-to-program, grafana, privilege-escalation, command-execution.</description><category>web</category><category>Critical</category><category>rce</category><category>percona-pmm</category><category>postgresql</category><category>copy-to-program</category><category>grafana</category><category>privilege-escalation</category><category>command-execution</category></item><item><title>Apache Superset Authenticated SQL Injection via sqlExpression/where Bypass — CVE-2026-23980</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23980-superset-sqli/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23980-superset-sqli/</guid><description>Medium severity (CVSS 6.5) — web · CVE-2026-23980. Status: PoC. Affects: Apache Superset. Tags: apache-superset, sql-injection, error-based-sqli, postgresql, authenticated, api, python, cwe-89.</description><category>web</category><category>Medium</category><category>apache-superset</category><category>sql-injection</category><category>error-based-sqli</category><category>postgresql</category><category>authenticated</category><category>api</category><category>python</category><category>cwe-89</category></item><item><title>PostgreSQL Referential-Integrity Owner-Switched Implicit Cast RCE</title><link>https://poc.intelseclab.com/pocs/network/2026-07-04_postgres-ri-owner-switched-cast-rce/</link><pubDate>Sat, 04 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-04_postgres-ri-owner-switched-cast-rce/</guid><description>High severity — network · None assigned as of 2026-07-04. Status: PoC. Affects: PostgreSQL (server). Tags: postgresql, privilege-escalation, referential-integrity, implicit-cast, command-execution, database, uncoordinated-disclosure.</description><category>network</category><category>High</category><category>postgresql</category><category>privilege-escalation</category><category>referential-integrity</category><category>implicit-cast</category><category>command-execution</category><category>database</category><category>uncoordinated-disclosure</category></item><item><title>Splunk Enterprise Pre-Auth RCE via PostgreSQL Sidecar (CVE-2026-20253)</title><link>https://poc.intelseclab.com/pocs/web/2026-06-28_cve-2026-20253-splunk-preauth-rce/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-06-28_cve-2026-20253-splunk-preauth-rce/</guid><description>Critical severity — web · CVE-2026-20253. Status: PoC. Affects: Splunk Enterprise. Tags: pre-auth, RCE, PostgreSQL, Splunk, CISA-KEV, lo-export, sidecar, unauthenticated, file-write.</description><category>web</category><category>Critical</category><category>pre-auth</category><category>RCE</category><category>PostgreSQL</category><category>Splunk</category><category>CISA-KEV</category><category>lo-export</category><category>sidecar</category><category>unauthenticated</category><category>file-write</category></item><item><title>Drupal Core PostgreSQL SQL Injection (CVE-2026-9082)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-30_drupal-core-postgresql-sql-injection/</link><pubDate>Sat, 30 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-30_drupal-core-postgresql-sql-injection/</guid><description>Critical severity — web · CVE-2026-9082 / SA-CORE-2026-004. Status: Patched. Affects: Drupal Core. Tags: SQLi, Drupal, PostgreSQL, JSON:API, unauthenticated, data-exfiltration.</description><category>web</category><category>Critical</category><category>SQLi</category><category>Drupal</category><category>PostgreSQL</category><category>JSON:API</category><category>unauthenticated</category><category>data-exfiltration</category></item></channel></rss>