🔐 CVE Alert

CVE-2026-66838

UNKNOWN 0.0

SQL injection via the :comment option in Postgrex.stream/4

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex allows SQL Injection via the :comment option of Postgrex.stream/4. An attacker who can influence that value can close the comment delimiter with */ and extend the streamed statement with their own clauses, which execute under the connection's role. Ecto exposes the same option through Ecto.Repo.stream/2. Postgrex appends the comment by concatenating it into the statement text sent in the Parse message, without escaping or rejecting */. The option is validated by comment_not_present!/1 at every other execution point; stream/4 never calls it. Because Parse accepts a single command, the injection is confined to the streamed statement and further statements cannot be chained. This issue affects postgrex: from 0.19.3 before 0.22.4.

CWE CWE-89
Vendor elixir-ecto
Product postgrex
Published Aug 7, 2026
Last Updated Aug 7, 2026
Stay Ahead of the Next One

Get instant alerts for elixir-ecto postgrex

Be the first to know when new unknown vulnerabilities affecting elixir-ecto postgrex are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

elixir-ecto / postgrex
0.19.3 < 0.22.4
elixir-ecto / postgrex
4971a2722fa72f8e1b54a2c403cad4c43916e36d < *

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/elixir-ecto/ecto/security/advisories/GHSA-3gww-3f36-2388 cna.erlef.org: https://cna.erlef.org/cves/CVE-2026-66838.html osv.dev: https://osv.dev/vulnerability/EEF-CVE-2026-66838 github.com: https://github.com/elixir-ecto/postgrex/commit/e1ecba618ddea4cee2556bd6ad9b6285e05f9d3c github.com: https://github.com/elixir-ecto/postgrex/commit/4011be852c99dc61ddb98cb01aa41e8775a0e3dd

Credits

Snehil Shah José Valim Jonatan Männchen / EEF