CVE-2026-65314
MEDIUMElectric Postgres Sync Excluded-Column Value Inference via Subset Where Clauses
Title source: cnaDescription
Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability that allows attackers to infer the values of excluded columns by crafting subset where clause conditions against shape responses. Attackers can observe whether subset where conditions match rows to deduce sensitive field data even though those columns are not returned in shape responses, bypassing column-based access restrictions.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory
https://github.com/electric-sql/electric/security/advisories/GHSA-c82q-v86f-c87f
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/electric-postgres-sync-excluded-column-value-inference-via-subset-where-clauses
Scores
CVSS v3
4.3
EPSS
0.0023
EPSS Percentile
13.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-203
Status
published
Products (1)
ElectricSQL/Electric Postgres Sync
< 1.6.10
Published
Jul 21, 2026
Tracked Since
Jul 22, 2026