WhisperX tag archive

#Database Security

This page collects WhisperX intelligence signals tagged #Database Security. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (5)

The Lab · 2026-03-31 11:27:19 · GitHub Issues

2. Kysely SQL Injection Vulnerability Exposed: CVE-2026-32763 in JSON Path Compilation

A critical SQL injection vulnerability has been disclosed in the popular Kysely SQL query builder, exposing applications using its MySQL and SQLite dialects to potential data manipulation and exfiltration attacks. The flaw, tracked as CVE-2026-32763, resides in versions through 0.28.11 and stems from improper handling ...

The Lab · 2026-04-03 20:27:12 · GitHub Issues

3. Sequelize v6.37.8 Patches Critical SQL Injection Vulnerability (CVE-2026-30951)

A critical security flaw in the popular Sequelize ORM for Node.js has been patched, exposing countless applications to SQL injection attacks. The vulnerability, tracked as CVE-2026-30951, resides in the library's JSON/JSONB `where` clause processing. Specifically, the `_traverseJSON()` function splits JSON path keys on...

The Lab · 2026-04-29 14:24:10 · Habr

4. pg_pathcheck: открытый инструмент для проверки качества проприетарных доработок PostgreSQL на стороне клиента

При использовании проприетарных версий PostgreSQL от вендоров возникает фундаментальная проблема доверия: код оригинальной СУБД остаётся открытым и проверенным, а вот фичи, добавленные вендором, остаются закрытыми. Бренд компании-поставщика не заменяет объективную верификацию — и именно этот пробел призван закрыть моду...

The Lab · 2026-05-09 11:01:39 · Mastodon:mastodon.social:#infosec

5. Critical 9.8 Severity Vulnerability in Nornicdb: CVE-2026-42072 Exposes Config Handling Flaw Pre-Patch

A critical severity vulnerability tracked as CVE-2026-42072 has been disclosed in Nornicdb, a distributed low-latency database system combining graph, vector, and temporal MVCC capabilities with sub-millisecond HNSW search performance. The flaw carries a CVSS score of 9.8, placing it at the highest end of the critical ...