{"id":"CVE-2026-66838","summary":"SQL injection via the :comment option in Postgrex.stream/4","details":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex allows SQL Injection via the :comment option of Postgrex.stream/4. An attacker who can influence that value can close the comment delimiter with */ and extend the streamed statement with their own clauses, which execute under the connection's role. Ecto exposes the same option through Ecto.Repo.stream/2.\n\nPostgrex appends the comment by concatenating it into the statement text sent in the Parse message, without escaping or rejecting */. The option is validated by comment_not_present!/1 at every other execution point; stream/4 never calls it. Because Parse accepts a single command, the injection is confined to the streamed statement and further statements cannot be chained.\n\nThis issue affects postgrex: from 0.19.3 before 0.22.4.","aliases":["EEF-CVE-2026-66838","GHSA-3gww-3f36-2388"],"modified":"2026-08-09T03:46:53.549168102Z","published":"2026-08-07T12:20:02.376Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"0.19.3"},{"fixed":"0.22.4"},{"introduced":"4971a2722fa72f8e1b54a2c403cad4c43916e36d"},{"fixed":"*"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"introduced":"0.19.3"},{"fixed":"0.22.4"}],"source":"CPE_FIELD"},{"source":"DESCRIPTION","extracted_events":[{"fixed":"Ecto.Repo.stream"},{"introduced":"0.19.3"},{"fixed":"0.22.4"}]}],"cna_assigner":"EEF","cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66838.json"},"references":[{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-66838.html"},{"type":"WEB","url":"https://github.com"},{"type":"WEB","url":"https://osv.dev/vulnerability/EEF-CVE-2026-66838"},{"type":"WEB","url":"https://repo.hex.pm"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66838.json"},{"type":"ADVISORY","url":"https://github.com/elixir-ecto/ecto/security/advisories/GHSA-3gww-3f36-2388"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66838"},{"type":"FIX","url":"https://github.com/elixir-ecto/postgrex/commit/4011be852c99dc61ddb98cb01aa41e8775a0e3dd"},{"type":"FIX","url":"https://github.com/elixir-ecto/postgrex/commit/e1ecba618ddea4cee2556bd6ad9b6285e05f9d3c"},{"type":"PACKAGE","url":"https://github.com/elixir-ecto/postgrex"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elixir-ecto/postgrex","events":[{"introduced":"0"},{"fixed":"4011be852c99dc61ddb98cb01aa41e8775a0e3dd"},{"fixed":"e1ecba618ddea4cee2556bd6ad9b6285e05f9d3c"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v0.22.2","v0.22.1","v0.21.1","v0.21.0","v0.20.0","v0.19.3","v0.19.2","v0.19.1","v0.19.0","v0.18.0","v0.17.5","v0.17.4","v0.17.3","v0.17.2","v0.17.1","v0.17.0","v0.16.5","v0.16.4","v0.16.3","v0.16.2","v0.16.1","v0.16.0","v0.15.9","v0.15.8","v0.15.7","v0.15.6","v0.15.5","v0.15.4","v0.15.3","v0.15.2","v0.15.1","v0.15.0","v0.14.2","v0.14.1","v0.14.0","v0.14.0-rc.0","v0.12.1","v0.13.2","v0.13.1","v0.13.0","0.13.0-rc.0","v1.0.0-rc.1","v1.0.0-rc.0","v0.12.0","v0.11.2","v0.11.1","v0.11.0","prep_ex","v0.10.0","v0.9.1","v0.9.0","v0.8.4","v0.8.3","v0.8.2","v0.8.1","v0.7.0","v0.6.0","v0.5.5","v0.5.4","v0.5.3","v0.5.2","v0.5.1","v0.5.0","v0.4.2","v0.4.1","v0.4.0","v0.3.1","v0.3.0","v0.2.1","v0.2.0","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66838.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"}]}