<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Pg_partman - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/pg_partman/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 21 Sep 2026 13:53:40 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/pg_partman/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Multiple Vulnerabilities in pg_partman PostgreSQL Extension</title><link>https://feed.craftedsignal.io/briefs/2026-09-pg-partman/</link><pubDate>Mon, 21 Sep 2026 13:53:40 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-pg-partman/</guid><description>The pg_partman extension for PostgreSQL is susceptible to multiple vulnerabilities allowing authenticated, remote attackers to perform Denial of Service, authorization bypass, and SQL injection, ultimately leading to privilege escalation and arbitrary command execution.</description><content:encoded><![CDATA[<p>The pg_partman extension, widely used for time-based partitioning in PostgreSQL databases, is affected by a series of security flaws. These vulnerabilities permit a remote, authenticated attacker to manipulate database functions to trigger a Denial of Service (DoS), bypass authorization checks, and conduct SQL injection attacks. By exploiting these flaws, an attacker can escalate their privileges within the database management system and transition to executing arbitrary operating system commands on the host server. The impact is significant for organizations relying on pg_partman for large-scale data partitioning, as it provides a direct path from database access to full system compromise.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for complete compromise of the underlying host, including data exfiltration, database destruction via DoS, and the establishment of persistent backdoors. Organizations utilizing pg_partman in sensitive environments are at risk of unauthorized administrative access and lateral movement if the database service account has excessive operating system permissions.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize auditing PostgreSQL extensions and configurations where pg_partman is deployed. Limit the privileges of database service accounts to prevent successful command execution on the host OS even if the database is compromised. Update the pg_partman extension to the latest version immediately upon vendor release.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>postgresql</category><category>vulnerability</category><category>sql-injection</category><category>privilege-escalation</category></item></channel></rss>