CVE-2026-50735

NameCVE-2026-50735
Descriptionpglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol messages before copying them, resulting in an out-of-bounds read. A party acting as the publisher for a subscription, for example a non-PostgreSQL endpoint that speaks the pglogical replication protocol, can return crafted messages that cause the subscriber's apply worker to read beyond the bounds of an allocated buffer, disclosing adjacent process memory or crashing the worker. To exploit the issue an attacker must be able to direct a subscription at an endpoint they control. In default installations this requires privileges normally reserved for a superuser, so the issue is most relevant to managed deployments where the ability to create subscriptions has been delegated to non-superuser roles.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
pglogical (PTS)bullseye2.3.3-3+deb11u1vulnerable
bookworm2.4.2-3vulnerable
trixie2.4.5-1vulnerable
forky2.4.7-1vulnerable
sid2.4.8-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
pglogicalsource(unstable)2.4.8-1

Notes

https://github.com/2ndQuadrant/pglogical/releases/tag/REL2_4_8
https://www.enterprisedb.com/docs/security/advisories/cve202650735/
Fixed by: https://github.com/2ndQuadrant/pglogical/commit/57bc728a6b4fb6c70dc50edd4f385374f88e1e87 (REL2_4_8)

Search for package or bug name: Reporting problems