VYPR

pglogical

by Pglogical

CVEs (2)

  • CVE-2021-3515MedJun 1, 2021
    risk 0.44cvss 6.7epss 0.00

    A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB privileges on a PostgreSQL server can craft a database name that allows execution of shell commands as the postgresql user when calling…

  • CVE-2026-50738MedJul 28, 2026
    risk 0.34cvss 5.3epss 0.01

    A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced after the underlying slot has been freed or recycled during normal worker lifecycle events. The condition is reachable during normal replication operation,…