← Back to Resources
Open Source NewsAugust 14, 20252 min read

PostgreSQL Security Release Fixes pg_dump Code Injection

By BIOS Founding Team

PostgreSQL Security Release Fixes pg_dump Code Injection

Fixed CVE-2025-8714 (CVSS 8.8), a pg_dump vulnerability letting a malicious superuser inject code executed at restore time, and CVE-2025-8713, an optimizer-statistics leak that could expose row-security-protected data.

Full details: https://www.postgresql.org/support/security/CVE-2025-8714/