{"id":"CVE-2026-62845","summary":"Kamaji: SQL injection via unescaped datastore identifiers in PostgreSQL/MySQL drivers","details":"Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivers build DDL statements by interpolating the user-supplied DataStoreUsername/DataStoreSchema directly into SQL via fmt.Sprintf, without escaping identifiers. These fields have no format validation, so a value containing a quote character breaks out of the quoted identifier — SQL injection executed over Kamaji's root connection to the shared datastore. etcd driver is not affected.This issue is fixed in version 26.7.4-edge.","aliases":["GHSA-r47v-ppwp-fh4r"],"modified":"2026-08-04T11:51:16.886861716Z","published":"2026-07-30T21:10:10.512Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62845.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-89"]},"references":[{"type":"WEB","url":"https://github.com/clastix/kamaji/releases/tag/26.7.4-edge"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62845.json"},{"type":"ADVISORY","url":"https://github.com/clastix/kamaji/security/advisories/GHSA-r47v-ppwp-fh4r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62845"},{"type":"FIX","url":"https://github.com/clastix/kamaji/commit/6a9f3e10ae408e7948e2aca2db694791a299e79c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/clastix/kamaji","events":[{"introduced":"0"},{"fixed":"5e576071f010baa587f8de9027b66324dcea7af5"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"26.6.4-edge"}],"source":"AFFECTED_FIELD"}}],"versions":["26.6.3-edge","26.6.2-edge","26.6.1-edge","26.5.5-edge","26.5.4-edge","26.5.3-edge","26.5.2-edge","26.4.5-edge","26.4.4-edge","26.4.3-edge","26.4.2-edge","26.3.6-edge","26.3.5-edge","26.3.4-edge","26.3.3-edge","26.3.2-edge","edge-26.2.5","edge-26.2.4","edge-26.2.3","edge-26.2.2","edge-26.1.5","edge-26.1.4","edge-26.1.3","edge-26.1.2","edge-25.12.5","edge-25.12.4","edge-25.12.3","edge-25.12.2","edge-25.12.1","edge-25.11.5","edge-25.11.4","edge-25.11.3","edge-25.11.2","edge-25.10.5","edge-25.10.4","edge-25.10.3","edge-25.10.2","edge-25.9.5","edge-25.9.4","edge-25.9.3","edge-25.9.2","edge-25.9.1","edge-25.8.5","edge-25.8.4","edge-25.8.3","edge-25.8.2","edge-25.7.5","edge-25.7.3","edge-25.7.2","edge-25.7.1","edge-25.4.1","edge-25.3.2","edge-25.03.1","edge-24.12.1","edge-24.10.1","edge-24.9.2","edge-24.9.1","edge-24.8.2","edge-24.8.1","edge-24.7.1","v1.0.0","helm-v1.0.0","v0.6.1","helm-v0.16.1","v0.6.0","helm-v0.16.0","v0.5.0","helm-v0.15.2","v0.4.2","helm-v0.15.1","helm-v0.15.0","v0.4.1","helm-v0.14.1","v0.4.0","helm-v0.14.0","v0.3.6","helm-v0.13.1","helm-v0.13.0","helm-v0.12.9","helm-v0.12.8","v0.3.5","helm-v0.12.7","helm-v0.12.6","v0.3.4","helm-v0.12.5","v0.3.3","helm-v0.12.4","v0.3.2","helm-v0.12.3","v0.3.1","helm-v0.12.2","helm-v0.12.1","v0.3.0","helm-v0.12.0","v0.2.3","helm-v0.11.5","v0.2.2","helm-v0.11.4","helm-v0.11.3","v0.2.1","helm-v0.11.2","helm-v0.11.1","v0.2.0","helm-v0.11.0","v0.2.0-rc0","helm-v0.10.2","helm-v0.10.1","v0.1.1","helm-v0.10.0","helm-v0.9.4","helm-v0.9.3","v0.1.0","helm-v0.9.2","helm-v0.9.1","helm-v0.8.0","helm-v0.7.0","helm-v0.6.0","helm-v0.5.0","helm-v0.4.0","helm-v0.3.0","helm-v0.2.0","v0.1.0-rc0","v0.0.2-rc0","v0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-62845.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"}]}