VYPR
High severity8.0OSV Advisory· Published Nov 10, 2025· Updated Apr 15, 2026

CVE-2025-12967

CVE-2025-12967

Description

An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users.

We recommend customers upgrade to the following versions: AWS JDBC Wrapper to v2.6.5, AWS Go Wrapper to 2025-10-17, AWS NodeJS Wrapper to v2.0.1, AWS Python Wrapper to v1.4.0 and AWS PGSQL ODBC driver to v1.0.1

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
aws_advanced_python_wrapperPyPI
< 1.4.01.4.0

Affected products

1

Patches

5

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

15

News mentions

0

No linked articles in our index yet.