Tools

Why SolarWinds WHD is not affected by CVE-2025-1094

This article explains why SolarWinds Web Help Desk (WHD) is not affected by CVE-2025-1094.

First published date

3/10/2025 3:35 PM

Last published date

6/23/2026 10:11 PM

Overview

In 2025, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2025-1094.

CVE-2025-1094 is a SQL injection vulnerability resulting from improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() which allow a database input provider to achieve SQL injection in certain usage patterns. This issue affects PostgreSQL versions before 17.3, 16.7, 15.11, 14.16, and 13.19.

The vulnerability described in this CVE affects numerous software companies.

Product section

Web Help Desk

Cause

CVE-2025-1094

Resolution

This vulnerability affects only applications that use the vulnerable functions indicated above. SolarWinds Web Help Desk (WHD) does not use the affected functions and also has query parameterization in place, which mitigates SQL injection attacks, and is therefore not affected by this vulnerability.