Bulletin ID: AWS-2025-028** Scope: AWS Content Type:** Important (requires attention) Publication Date: 2025/11/10 10:15 AM PDT ** Description:**

Amazon Aurora PostgreSQL a fully managed relational database engine that’s compatible with PostgreSQL.

We identified CVE-2025-12967, an issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users.

Impacted versions:

  • AWS JDBC Wrapper <2.6.5
  • AWS Go Wrapper <2025-10-17
  • AWS NodeJS Wrapper <2.0.1
  • AWS Python Wrapper <1.4.0
  • AWS ODBC driver <1.0.1 …

Similar Posts

Loading similar posts...

Keyboard Shortcuts

Navigation
Next / previous item
j/k
Open post
oorEnter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help