HIGH
pgpointcloud
CVE published 2026-09-25
CVE-2026-100387
CVE-2026-100387 is a high-severity vulnerability in pgPointcloud, a PostgreSQL extension for working with point cloud data. The vulnerability allows authenticated database users to read adjacent heap memory by supplying crafted pcpatch values with attacker-controlled size fields. This can be used to exfiltrate data or crash the PostgreSQL backend. The vulnerability is caused by a heap out-of-bounds read i [truncated]