What is CVE-2026-50735?
A vulnerability in pglogical's apply worker where insufficient validation of field lengths in incoming replication protocol messages leads to an out-of-bounds read. A malicious publisher, especially a non-PostgreSQL endpoint, could exploit this to cause information disclosure on the subscriber. Upgrading to the latest version of pglogical is recommended.
Azərbaycanca: Bu, pglogical-ın tətbiq işçisində (apply worker) daxil olan replikasiya protokolu mesajlarındakı sahələrin uzunluğunun kifayət qədər yoxlanılmaması nəticəsində yaranan sərhəddən kənar oxuma (out-of-bounds read) zəifliyidir. Xüsusilə etibarsız nəşriyyatçı (publisher) rolunda olan qeyri-PostgreSQL uç nöqtələri bu yolla hədəf sistemlərdə məlumat sızmasına səbəb ola bilər. Təsirə məruz qalmamaq üçün pglogical-ın ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
In which component of pglogical was CVE-2026-50735 discovered, and what can happen as a result of exploitation?
The vulnerability was discovered in the apply worker component of pglogical. As a result of exploitation, particularly by a malicious publisher acting as a non-PostgreSQL endpoint, it can lead to information disclosure on the subscriber.
What is the root cause of the CVE-2026-50735 vulnerability?
The root cause of the vulnerability is insufficient validation of field lengths in incoming replication protocol messages within pglogical's apply worker.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.