VDB
Sign up
—

PYSEC-2026-1766

pg8000 SQL injection vulnerability via a specially crafted Python list input

Quick fix

PYSEC-2026-1766 — pg8000: upgrade to the fixed version with the command below.

pip install --upgrade 'pg8000>=1.31.5'

Details

SQL injection vulnerability in tlocke pg8000 1.31.4 allows remote attackers to execute arbitrary SQL commands via a specially crafted Python list input to function pg8000.native.literal.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pg8000
Introduced in: 0Fixed in: 1.31.5
Fixpip install --upgrade 'pg8000>=1.31.5'

References