pgsql extension does not check for errors during escaping
CVSS v3
5.9
MEDIUM
EPSS Score
0.6%
exploit probability
CISA KEV
No
known exploited
Exploitation
none
SSVC status
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* pgsql and pdo_pgsql escaping functions do not check if the underlying quoting functions returned errors. This could cause crashes if Postgres server rejects the string as invalid.
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* pgsql and pdo_pgsql escaping functions do not check if the underlying quoting functions returned errors. This could cause crashes if Postgres server rejects the string as invalid.
Active exploitation of CVE-2025-1735 has not been confirmed. The EPSS score is 0.6%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2025-1735 has a CVSS v3 base score of 5.9 (MEDIUM severity), with vector string 3.1.
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).