—
PYSEC-2026-1766
pg8000 SQL injection vulnerability via a specially crafted Python list input
Quick fix
PYSEC-2026-1766 — pg8000: upgrade to the fixed version with the command below.
pip install --upgrade 'pg8000>=1.31.5'Details
SQL injection vulnerability in tlocke pg8000 1.31.4 allows remote attackers to execute arbitrary SQL commands via a specially crafted Python list input to function pg8000.native.literal.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-61385[ADVISORY]
- https://codeberg.org/tlocke/pg8000[PACKAGE]
- https://codeberg.org/tlocke/pg8000/commit/8663c746b02286c32f19c385f0e2e5da9e4fa140[WEB]
- https://github.com/bmcyver/vulnerability-research/tree/main/CVE-2025-61385[WEB]
- https://pypi.org/project/pg8000[PACKAGE]
- https://github.com/advisories/GHSA-wq2g-r956-j8cc[ADVISORY]