Executive brief
pglogical is a logical replication system for PostgreSQL databases used to synchronize data between different servers. A security vulnerability has been identified where a low-privileged user can trigger a memory error during normal replication tasks. In most cases, this will cause the database replication service to crash, leading to a loss of data synchronization; however, in extreme scenarios, it could allow an attacker to execute unauthorized code on the database server.
Technical details
A use-after-free (CWE-416) vulnerability exists in the worker signaling component of pglogical. The flaw occurs when a worker structure is dereferenced after its associated slot has been freed or recycled during lifecycle events (start, stop, or restart). An attacker with low privileges can trigger this condition by manipulating the timing of these worker operations. While the most common outcome is a denial-of-service (DoS) via worker crashes, the memory corruption could potentially be exploited for remote code execution (RCE) within the context of the PostgreSQL backend process. The issue is addressed in pglogical version 2.4.8.
Affected products
- EnterpriseDB pglogical 2.x before 2.4.8
Timeline
- 2026-07-28: advisory: Initial disclosure by EnterpriseDB
- 2026-07-28: patched: Fix released in version 2.4.8