What is CVE-2026-6464?
CVE-2026-6464: Untrusted data inclusion in PostgreSQL's psql COPY command may allow a server administrator to execute data lines as psql commands via error injection when the 'COPY FROM STDIN' or '\copy FROM STDIN' command fails before the server indicates it is ready for input rows. Users should update PostgreSQL or avoid COPY operations from untrusted sources.
Azərbaycanca: CVE-2026-6464: PostgreSQL-in psql alətində COPY əmri vasitəsilə etibarsız məlumat daxil edilərsə, server administratoru xəta inyeksiyası yolu ilə məlumat sətirlərini psql əmrləri kimi icra etdirə bilər. Bu, "COPY FROM STDIN" və ya "\copy FROM STDIN" əmrlərinin uğursuz icrası zamanı baş verir. İstifadəçilərə PostgreSQL-i yeniləmək və ya təsdiqlənməmiş mənbələrdən COPY əməliyyatları aparmamaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: PostgreSQL
FAQ2
What is the CVE-2026-6464 vulnerability?
CVE-2026-6464 is a vulnerability where untrusted data inclusion in PostgreSQL's psql COPY command may allow a server administrator to execute data lines as psql commands via error injection.
How to protect against this vulnerability?
Users should update PostgreSQL or avoid COPY operations from untrusted sources.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.