Easy Fuud
Security

Security update: patched PostgreSQL vulnerability (CVE-2026-15741)

Patched — no action needed

A vulnerability in the open-source database software we run was published by the PostgreSQL project. We have updated to the fixed version. Your account, your orders and your payment details are unaffected, and there is nothing you need to do.

On 13 August 2026 the PostgreSQL project disclosed CVE-2026-15741, a SQL injection flaw in the way PostgreSQL converts certain expressions back into SQL text. It carries a CVSS v3.1 base score of 8.8 (High). The fix ships in PostgreSQL 14.24, 15.19, 16.15, 17.11 and 18.5.

What it actually means

Exploiting the flaw requires an account that already owns objects inside the database — it is not something that can be triggered from the ordering site, the till or the kitchen app. Easy Fuud’s database is not reachable from the public internet, and no restaurant, staff or diner account has that level of access. The practical exposure was therefore low. We patch every high-severity database advisory regardless, on the principle that "low" is not "none".

What we did

  • Reviewed the advisory the day it was published and confirmed which of our environments ran an affected version.
  • Upgraded production and staging to a patched PostgreSQL release.
  • Verified the running version after the upgrade, and re-ran the deployment checks so ordering, payments and printing were confirmed working afterwards.

What you need to do

Nothing. There is no password to reset, no update to install, and no change to how you take orders. The upgrade was applied without interrupting service.

Why we are telling you

Most platforms patch a dependency like this quietly and never mention it. We would rather publish the boring ones too, so that when something does need your attention you already know what our notices look like and where to find them. Security questions are always welcome at support@easyfuud.com.