Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-8713— PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table

CVSS 3.1 · Low EPSS 0.05% · P15
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-8713

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table
Source: NVD (National Vulnerability Database)
Vulnerability Description
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
CWE-1230
Source: NVD (National Vulnerability Database)
Vulnerability Title
PostgreSQL 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
PostgreSQL是PostgreSQL组织的一套自由的对象关系型数据库管理系统。该系统支持大部分SQL标准并且提供了许多其他特性,例如外键、触发器、视图等。 PostgreSQL 17.6版本、16.10版本、15.14版本、14.19版本和13.22之前版本存在安全漏洞,该漏洞源于优化器统计信息可能绕过视图ACL和行安全策略泄露采样数据。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-PostgreSQL 17 ~ 17.6 -

II. Public POCs for CVE-2025-8713

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-8713

登录查看更多情报信息。

Same Patch Batch · n/a · 2025-08-14 · 23 CVEs total

CVE-2025-87148.8 HIGHPostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client
CVE-2025-87158.8 HIGHPostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in re
CVE-2025-89613.3 LOWLibTIFF tiffcrop tiffcrop.c main memory corruption
CVE-2025-51965OURPHP 安全漏洞
CVE-2025-50862Altus Cars Lotus Cars Android app 安全漏洞
CVE-2025-50861Altus Cars Lotus Cars Android app 安全漏洞
CVE-2025-52335EyouCMS 安全漏洞
CVE-2025-51986SILA Embedded Solutions Freemodbus 安全漏洞
CVE-2025-50817python-future 安全漏洞
CVE-2023-43687Malwarebytes 安全漏洞
CVE-2025-50515EmpireSoft Empirebak 安全漏洞
CVE-2023-43683Malwarebytes 安全漏洞
CVE-2023-43692Malwarebytes 安全漏洞
CVE-2025-50518libcoap 安全漏洞
CVE-2023-43694Malwarebytes 安全漏洞
CVE-2025-27847ESPEC North America Web Controller 3 安全漏洞
CVE-2025-27846ESPEC North America Web Controller 3 安全漏洞
CVE-2025-27845ESPEC North America Web Controller 3 安全漏洞
CVE-2025-43983KuWFi CPF908-CP5 安全漏洞
CVE-2024-53946KuWFi 4G LTE AC900 安全漏洞

Showing top 20 of 23 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2025-8713

No comments yet


Leave a comment