Executive brief
A vulnerability exists in the Postgrex library, which is used by Elixir applications to communicate with PostgreSQL databases. If an application allows users to influence the names of database notification channels, an attacker can provide a specially crafted name that breaks the connection. This results in a denial of service where the application stops receiving important database updates or notifications for all users sharing that connection.
Technical details
A SQL injection vulnerability exists in Postgrex.Notifications due to improper sanitization of channel names during reconnection. While the library escapes double quotes, it fails to escape the dollar-quote delimiter ($) used in the anonymous code block (DO $BEGIN...END$) within handle_connect/1. An attacker providing a channel name containing $ can prematurely terminate the dollar-quoted string, causing a syntax error when the library attempts to replay subscriptions. This results in a persistent failure to re-establish subscriptions upon reconnection, leading to a denial of service for all notifications on the affected connection. Arbitrary SQL execution is mitigated by existing double-quote escaping, but the connection remains broken until the malicious channel is removed or the library is patched.
Affected products
- elixir-ecto postgrex from 0.16.0 before 0.22.3
Timeline
- 2026-07-09: advisory: GitHub Security Advisory published
- 2026-07-10: disclosed: CVE published to NVD