CVE-2026-17543
SQL injection in ext-pgsql via E'...' backslash breakout
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
| CWE | CWE-89 |
| Vendor | php group |
| Product | php |
| Published | Jul 30, 2026 |
| Last Updated | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for php group php
Be the first to know when new unknown vulnerabilities affecting php group php are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
PHP Group / PHP
8.2.* < 8.2.33 8.3.* < 8.3.33 8.4.* < 8.4.24 8.5.* < 8.5.9
References
Credits
ExPatch-LLC Alexandre Daubois - The PHP Foundation Ilija Tovilo - The PHP Foundation Matteo Beccati Jakub Zelenka - The PHP Foundation