CVE-2025-1735 Information

Description

In PHP versions:8.1. before 8.1.33 8.2. before 8.2.29 8.3. before 8.3.23 8.4. pgsql and pdo_pgsql escaping functions do not check if the underlying quoting functions returned errors. This could cause crashes if Postgres server rejects the string as invalid.

Reference

https://github.com/php/php-src/security/advisories/GHSA-hrwm-9436-5mv3

CNNVD-202507-1799 (Published: 2025-07-13)

Share on: