CVE-2026-50738

Source
https://cve.org/CVERecord?id=CVE-2026-50738
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50738.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-50738
Downstream
Published
2026-07-28T19:17:36.967Z
Modified
2026-08-27T19:00:31.974526Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced after the underlying slot has been freed or recycled during normal worker lifecycle events. The condition is reachable during normal replication operation, including by a low-privileged user able to influence worker start, stop, and restart timing through permitted pglogical operations. In the typical case the condition crashes replication workers, causing an availability impact. In the worst case a use-after-free in a PostgreSQL backend can be leveraged as a remote code execution primitive at the privilege of that backend.

References

Affected packages

Git / github.com/2ndquadrant/pglogical

Affected ranges

Type
GIT
Repo
https://github.com/2ndquadrant/pglogical
Events
Database specific
Show details
{
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:enterprisedb:pglogical:*:*:*:*:*:postgresql:*:*",
    "extracted_events": [
        {
            "introduced": "2.0.0"
        },
        {
            "fixed": "2.4.8"
        }
    ]
}

Affected versions

Other
REL2_0_0
REL2_0_1
REL2_1_0
REL2_1_1
REL2_2_0
REL2_2_1
REL2_2_2
REL2_3_0
REL2_3_1
REL2_3_2
REL2_3_3
REL2_3_4
REL2_4_0
REL2_4_1
REL2_4_2
REL2_4_3
REL2_4_4
REL2_4_5
REL2_4_6
REL2_4_7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50738.json"