Skip to main content
UNKNOWN

CVE-2026-17543

SQL injection in ext-pgsql via E'...' backslash breakout

CVSS v3

—

Unknown

EPSS Score

0.3 %

exploit probability, as of 2026-10-01

CISA KEV

No

known exploited

Exploitation

none

SSVC status

Description

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

Technical details

Published
2026-07-30
Last Modified
2026-07-31

Frequently asked questions

What is CVE-2026-17543?

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

Is CVE-2026-17543 actively exploited?

Active exploitation of CVE-2026-17543 has not been confirmed. Its EPSS score was 0.3% on 2026-10-01, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-17543?

A CVSS score has not been assigned to CVE-2026-17543 yet.

Is CVE-2026-17543 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key