Skip to main content

Vendor/product archive

electric / sync-service CVEs

Beta · best-effort

1 CVEs tagged to electric / sync-service1 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-40906

Published Apr 21, 2026

Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API is vulnerable to error-based SQL injection, allowing any a…

CVSS 9.9 · Critical
evidence mentions
5
Buzz score
35.4
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 1-1 of 1 CVEsPage 1 of 1