UNKNOWNhex →
SQL injection via the :comment option in Postgrex.stream/4
SQL injection via the :comment option in Postgrex.stream/4
Affected packages
- postgrex
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/elixir-ecto/ecto/security/advisories/GHSA-3gww-3f36-2388
- https://cna.erlef.org/cves/CVE-2026-66838.html
- https://github.com/elixir-ecto/postgrex/commit/e1ecba618ddea4cee2556bd6ad9b6285e05f9d3c
- https://github.com/elixir-ecto/postgrex/commit/4011be852c99dc61ddb98cb01aa41e8775a0e3dd
- https://hex.pm/packages/postgrex
Structured record: https://osv.dev/vulnerability/EEF-CVE-2026-66838
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta