PatchSiren

pgpointcloud CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH pgpointcloud CVE published 2026-09-25

CVE-2026-100387

CVE-2026-100387 is a high-severity vulnerability in pgPointcloud, a PostgreSQL extension for working with point cloud data. The vulnerability allows authenticated database users to read adjacent heap memory by supplying crafted pcpatch values with attacker-controlled size fields. This can be used to exfiltrate data or crash the PostgreSQL backend. The vulnerability is caused by a heap out-of-bounds read i [truncated]