Vulnerability Description
Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-supplied regConfig parameter directly into the generated SQL without parameterization or validation, making every code path that exposes regConfig to untrusted input a SQL injection sink. This vulnerability is fixed in 8.36.1.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/JasperFx/marten/commit/626249656829860b9c55895b5b6046b61a2a69
- https://github.com/JasperFx/marten/pull/4343
- https://github.com/JasperFx/marten/security/advisories/GHSA-vmw2-qwm8-x84c
FAQ
What is CVE-2026-45288?
CVE-2026-45288 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-supplied regConfig parameter directly into the generated...
How severe is CVE-2026-45288?
CVE-2026-45288 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-45288?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.