๐Ÿ” CVE Alert

CVE-2026-45288

CRITICAL 9.8

Marten has an SQL injection vulnerability in its full-text search regConfig parameter

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
9th

Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-supplied regConfig parameter directly into the generated SQL without parameterization or validation, making every code path that exposes regConfig to untrusted input a SQL injection sink. This vulnerability is fixed in 8.36.1.

CWE CWE-89
Vendor jasperfx
Product marten
Published May 28, 2026
Last Updated May 30, 2026
Stay Ahead of the Next One

Get instant alerts for jasperfx marten

Be the first to know when new critical vulnerabilities affecting jasperfx marten are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

JasperFx / marten
< 8.36.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/JasperFx/marten/security/advisories/GHSA-vmw2-qwm8-x84c github.com: https://github.com/JasperFx/marten/pull/4343 github.com: https://github.com/JasperFx/marten/commit/626249656829860b9c55895b5b6046b61a2a695f