


Perceptive Security
SOC/SIEM Consultancy

Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-supplied regConf…
Published:
27 May 2026 at 22:00:00
Alert date:
28 May 2026 at 22:04:22
Source:
nvd.nist.gov
Web Technologies, Database & Storage
CVE-2026-45288 affects Marten, a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to version 8.36.1, Marten's full-text search APIs were vulnerable to SQL injection through the regConfig parameter. The vulnerability occurred because user-supplied regConfig parameters were interpolated directly into generated SQL without proper parameterization or validation. This made every code path exposing regConfig to untrusted input a potential SQL injection attack vector. The issue has been fixed in version 8.36.1.
Technical details
Mitigation steps:
Affected products:
Marten
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45288
https://github.com/JasperFx/marten/commit/626249656829860b9c55895b5b6046b61a2a695f
https://github.com/JasperFx/marten/pull/4343
https://github.com/JasperFx/marten/security/advisories/GHSA-vmw2-qwm8-x84c
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
