PatchSiren

duckdb CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM duckdb CVE published 2026-08-03

CVE-2026-58139

The CVE-2026-58139 vulnerability in the DuckDB AWS extension allows any database user with SQL execution permissions to extract plaintext AWS credentials by calling the load_aws_credentials function with the redact_secret parameter set to false. This security policy bypass can be particularly impactful in managed environments where pg_duckdb is preloaded and an AWS credential chain such as IMDSv2, IRSA, E [truncated]