PatchSiren

PostGIS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH PostGIS CVE published 2026-09-13

CVE-2026-90775

PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. This vulnerability can cause the PostgreSQL backend process to crash and terminate all cluster sessions. The issue arises from inadequate input validation, allowing attackers to craft malicious rule rows with out-of-range Weight values. Defenders should pri [truncated]