CVE-2026-66838Disclosure(elixir-ecto / postgrex)

LOWCVSS 8.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex allows SQL Injection via the :comment option of Postgrex.stream/4. An attacker who can influence that value can close the comment delimiter with */ and extend the streamed statement with their own clauses, which execute under the connection's role. Ecto exposes the same option through Ecto.Repo.stream/2. Postgrex appends the comment by concatenating it into the statement text sent in the Parse message, without escaping or rejecting */. The option is validated by comment_not_present!/1 at every other execution point; stream/4 never calls it. Because Parse accepts a single command, the injection is confined to the streamed statement and further statements cannot be chained. This issue affects postgrex: from 0.19.3 before 0.22.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • postgrex

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Products
postgrex

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-07: 3Technical Details · 2026-08-07: 208-07
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-66838 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex allows SQL Injection via the :comment optio… https://www.cve.org/CVERecord?id=CVE-2026-66838

    Post summary

    The text announces CVE-2026-66838, describing an SQL Injection vulnerability in elixir‑ecto postgrex, but does not provide proof of concept, exploit code, or mitigation details.

    01010811
    57.9K followersView on X
  • MalwareObserver@MalwareObserver
    General

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-66838](https://cna.erlef.org/cves/CVE-2026-66838.html) Improper Neutralization of Speci... https://cna.erlef.org/cves/CVE-2026-66838.html #Vulnerability #CVE #ZeroDay

    Post summary

    A tweet linking to a CNA page about CVE‑2026‑66838 and briefly naming the vulnerability type, without any evidence of a PoC, exploit, active attack, or patch information.

    0000039
    18 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-66838 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex allows SQL Injection via the :comment optio… https://www.cve.org/CVERecord?id=CVE-2026-66838 ----- Traducción: CVE-2026-66838 Eli… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-66838, describing an SQL injection flaw in elixir‑ecto postgrex, without providing PoC, exploit details, or patch information.

    0000028
    98 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelixir-ectopostgrex---

Explore more