CVE-2026-17543 is an SQL-injection vulnerability in PHP's PostgreSQL extension (ext-pgsql). The extension improperly escapes backslashes in attacker-controlled parameters when PostgreSQL standard_conforming_strings is enabled. An attacker can use the resulting escape-sequence breakout to alter the intended SQL statement. The flaw affects PHP 8.2 before 8.2.33, PHP 8.3 before 8.3.33, PHP 8.4 before 8.4.24, and PHP 8.5 before 8.5.9. Distribution-maintained older PHP branches may also be affected where the vendor has not backported the fix.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a compact proof-of-concept for CVE-2026-17543, a critical SQL injection flaw in PHP's procedural PostgreSQL extension (ext/pgsql). The exploit is implemented in a single executable PHP script, poc.php, with Docker artifacts provided to reproduce the issue in an isolated environment. Repository structure: - poc.php: Main exploit/demo script. Connects to PostgreSQL using PGCONN or a localhost fallback, creates a users table, inserts seed rows, and demonstrates two exploit paths. - Dockerfile: Builds a vulnerable PHP CLI container (php:8.4.23-cli), installs libpq/pgsql support, copies poc.php, and runs it. - docker-compose.yml: Starts PostgreSQL 16 and the vulnerable PHP container, wiring PGCONN to the db service. - README.md: Documents the vulnerability, affected versions, payloads, expected output, and usage. Exploit capabilities: 1. Data exfiltration via pg_select(): The script uses payload zzz\' OR 1=1 -- to exploit vulnerable quoting behavior. On affected PHP versions, generated SQL uses E'...' and the backslash escapes a quote, allowing OR 1=1 to execute and return all rows. 2. Privilege escalation via pg_insert(): The payload eve\', true) -- is injected into the name field while admin is nominally set to false. On vulnerable builds, the injected SQL alters the VALUES clause so admin becomes true. 3. SQL visibility for verification: The script calls pg_select() and pg_insert() with PGSQL_DML_STRING to print the generated SQL, making the vulnerable E'...' quoting behavior directly observable. 4. Live execution against a database: After printing the generated SQL, it executes the insert and queries the resulting row to confirm whether admin was forced to true. The exploit is operational rather than merely descriptive: it performs real database operations and demonstrates successful exploitation when run on a vulnerable PHP build. It is not a framework module and not just a detector, although it also implicitly distinguishes patched from vulnerable behavior by comparing query results and generated SQL.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical, network-reachable Oracle Linux 9 PHP-package vulnerability addressed in ELSA-2026-612590. The supplied CVSS v3 vector indicates unauthenticated, low-complexity remote exploitation with high confidentiality, integrity, and availability impact.
A critical network-accessible vulnerability addressed by an Oracle Linux 9 PHP package security update. The supplied CVSS v3.0 vector is 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
A critical, network-reachable vulnerability affecting PHP packages on Oracle Linux 10. The supplied CVSS v3 vector indicates unauthenticated remote exploitation with high impact to confidentiality, integrity, and availability.
A PHP ext-pgsql SQL-injection vulnerability caused by improper backslash escaping. Red Hat addressed it by rebasing PHP to version 8.3.33 in RHEL 10.2.z.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.