CVE-2025-8713 is a low-severity vulnerability in PostgreSQL versions prior to 17.6, 16.10, 15.14, 14.19, and 13.22. It allows an authenticated user with low privileges to bypass view access controls and row security policies by crafting a leaky operator, thereby reading sampled data from optimizer statistics that should be inaccessible. The attack vector is network-based with high attack complexity, resulting in a low impact on confidentiality and no impact on integrity or availability. There is currently no public exploit code available, it is not being actively exploited, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | PostgreSQL | >= 0, < 13.22, >= 14, < 14.19, >= 15, < 15.14, >= 16, < 16.10, >= 17, < 17.6CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
postgresql: PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table
Aug 14, 2025PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table
Aug 12, 2025PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table
Jan 1, 2025PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table
PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table
PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table
PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table
PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table
PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table
PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table