Change record status: 
Project: 
Introduced in branch: 
10.6.x
Introduced in version: 
10.6.16
Description: 

What changed

In Drupal\Core\Entity\Query\Sql\pgsql\Condition::translateCondition(), passing an operator other than IN or NOT IN for a case-insensitive condition with an array value now throws an \InvalidArgumentException.

Why

The operator was previously concatenated directly into the SQL query without validation, creating a SQL injection vulnerability.

Before

No validation — any operator was silently accepted, but would produce invalid SQL and a database-level error for anything other than IN or NOT IN.

After

The following now throws \InvalidArgumentException when the field is case-insensitive on PostgreSQL:
$query->condition('field', ['foo', 'bar'], 'LIKE');

How to update your code

Replace any non-IN / non-NOT IN operator used with array values on case-insensitive fields with IN or NOT IN. If your code was already triggering a database error in this scenario, this change simply surfaces the failure earlier as a PHP exception.

Impacts: 
Module developers