Back Linuxsecurity Fedora 42 pgadmin4 Denial of Service Fix Advisory 2026
pgAdmin is the most popular and feature rich Open Source administration and development platform for PostgreSQL, the most advanced Open Source database in the world. Update Information : Update bundled devalue / svelte
pgAdmin is the most popular and feature rich Open Source administration and development
platform for PostgreSQL, the most advanced Open Source database in the world.
Update bundled devalue / svelte
* Fri Jan 16 2026 Sandro Mani - 9.11-2 - Regenerate vendor tarball to pull in newer devalue and svelte, fixes CVE-2026-22775 and CVE-2025-15265
* Fri Jan 16 2026 Sandro Mani - 9.11-2 - Regenerate vendor tarball to pull in newer devalue and svelte, fixes CVE-2026-22775 and CVE-2025-15265
[ 1 ] Bug #2430107 - CVE-2026-22774 pgadmin4: devalue vulnerable to denial of service due to memory exhaustion in devalue.parse [fedora-42] [ 2 ] Bug #2430108 - CVE-2026-22774 pgadmin4: devalue vulnerable to denial of service due to memory exhaustion in devalue.parse [fedora-43] [ 3 ] Bug #2430305 - CVE-2025-15265 pgadmin4: Svelte: Remote script execution via Cross-Site Scripting (XSS) in async hydration [fedora-43] [ 4 ] Bug #2430306 - CVE-2025-15265 pgadmin4: Svelte: Remote script execution via Cross-Site Scripting (XSS) in async hydration [fedora-42] [ 5 ] Bug #2430327 - CVE-2026-22775 pgadmin4: devalue: Denial of Service due to improper input validation [fedora-43] ... Read the Full Advisory
[ 1 ] Bug #2430107 - CVE-2026-22774 pgadmin4: devalue vulnerable to denial of service due to memory exhaustion in devalue.parse [fedora-42] [ 2 ] Bug #2430108 - CVE-2026-22774 pgadmin4: devalue vulnerable to denial of service due to memory exhaustion in devalue.parse [fedora-43] [ 3 ] Bug #2430305 - CVE-2025-15265 pgadmin4: Svelte: Remote script execution via Cross-Site Scripting (XSS) in async hydration [fedora-43] [ 4 ] Bug #2430306 - CVE-2025-15265 pgadmin4: Svelte: Remote script execution via Cross-Site Scripting (XSS) in async hydration [fedora-42] [ 5 ] Bug #2430327 - CVE-2026-22775 pgadmin4: devalue: Denial of Service due to improper input validation [fedora-43] ...
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e55e601165' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
