These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T13:19:16.747Z and has not been modified since then. The CVE-2026-6471 vulnerability in PostgreSQL allows a non-superuser with REPLICATION privilege to execute arbitrary code via logical decoding plugins; this issue affects versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24. The vulne [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T13:19:16.600Z and has not been modified since then. The vulnerability is caused by missing authorization in PostgreSQL DDL commands, allowing an object creator to achieve denial of service against ALTER and DROP operations on types by creating a dependency on the type. Many DDL operations did che [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T13:19:16.347Z and has not been modified since then. The CVE-2026-6464 vulnerability involves untrusted data inclusion in PostgreSQL psql COPY, potentially allowing a server administrator to execute data lines as psql commands via error injection. This occurs when the 'COPY FROM STDIN' or 'copy FR [truncated]
The CVE-2026-18408 vulnerability allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump. This vulnerability affects PostgreSQL versions before 18.6, 17.11, 16.15, 15.19, and 14.24. The vulnerability is related to the psql command and can be exploited through the pg_dump, pg_dumpall, and p [truncated]
The CVE-2026-18024 vulnerability involves a buffer over-read in the PostgreSQL ascii() SQL function, allowing a user to disclose up to 3 bytes after the end of a specific allocation by providing a crafted text value. This issue is similar to CVE-2026-2006 but with less impact. The vulnerability has a CVSS score of 4.3 and is classified as Medium severity. Affected versions include PostgreSQL before 18.6, [truncated]
The CVE-2026-16241 vulnerability is an integer underflow in the ECPG component of PostgreSQL. This issue allows a database server administrator to achieve temporary denial of service against the ECPG client by sending a specially crafted bytea value without the mandatory prefix. The client then overwrites a large memory region with bytes outside the attacker's control, typically resulting in a segmentatio [truncated]
The CVE-2026-16238 vulnerability is a type confusion issue in the PostgreSQL pg_restore_attribute_stats() function. This allows an object creator to execute arbitrary code as the operating system user running the database by conflating range and multirange values. The affected versions are within major version 18, specifically minor versions before PostgreSQL 18.6. Administrators and users of PostgreSQL d [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T13:17:45.957Z and has not been modified since then. This SQL injection vulnerability in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition, affecting expression deparse consumers broadly, including pg_dump, psql commands lik [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T13:17:45.523Z and has not been modified since then. The NVD entry is currently Modified. This vulnerability involves improper enforcement of message integrity in PostgreSQL GSSAPI support, allowing a user to negotiate GSSAPI contrary to pg_hba.conf rules via initial direct TLS connection. Affecte [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T13:17:45.277Z and has not been modified since then. The CVE-2026-14679 vulnerability is a stack buffer overflow in PostgreSQL argument name matching. This allows an object creator to potentially achieve unknown impacts via OUT parameter count, with the ability to write only 0x0 and 0x1 bytes. Aff [truncated]
The CVE-2026-14678 vulnerability is a buffer over-read issue in the pg_trgm index picksplit function of PostgreSQL. This might allow a table maintainer to infer limited memory values via the lossy signal of index split choices. The issue affects PostgreSQL versions before 18.6, 17.11, 16.15, 15.19, and 14.24. To mitigate this vulnerability, it is essential to apply vendor patches or upgrade to a non-vulne [truncated]
The CVE-2026-14677 vulnerability is an integer wraparound issue in PostgreSQL's pltcl and plperl for 32-bit builds. This problem allows an object creator to undersize an allocation and write out-of-bounds via crafted function bodies, potentially leading to arbitrary code execution as the operating system user running the database. Affected versions include those before PostgreSQL 18.6, 17.11, 16.15, 15.19 [truncated]
The CVE-2026-14673 vulnerability is an untrusted search path issue in the PostgreSQL amcheck function. This allows users with EXECUTE privilege on the amcheck function to execute arbitrary functions as the owners of expression indexes by manipulating the search path. The vulnerability affects multiple PostgreSQL versions, including 14.0 to 14.24, 15.0 to 15.19, 16.0 to 16.15, and 18.0 to 18.5. Affected Po [truncated]
Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 1 [truncated]
The CVE-2026-14671 vulnerability is a type confusion issue in the PostgreSQL module 'refint' that allows an object creator to execute arbitrary code as the operating system user running the database. This vulnerability affects PostgreSQL versions before 18.6, 17.11, 16.15, 15.19, and 14.24. The fix for this vulnerability was introduced in a non-security bug report and appears in the git repository with th [truncated]
The CVE-2026-14670 vulnerability is a heap buffer overflow in PostgreSQL's plperl return of a tied hash, allowing function owners to execute arbitrary code as the operating system user running the database. This vulnerability affects PostgreSQL versions before 18.6, 17.11, 16.15, 15.19, and 14.24. The vulnerability has a CVSS score of 8.8, indicating a high severity level. Users of these versions should a [truncated]
The CVE-2026-14669 vulnerability is a heap buffer overflow in the to_char(timestamptz) function of PostgreSQL. This vulnerability allows a user with the ability to choose a timezone to execute arbitrary code as the operating system user running the PostgreSQL database. The vulnerability is due to a long POSIX timezone abbreviation. Versions of PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24 are aff [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T13:17:44.137Z and has not been modified since then. The CVE-2026-14668 vulnerability involves a type confusion issue in PostgreSQL's ctid data type selectivity estimator. An object creator can exploit this to view calculations derived from an arbitrary 4-byte span of memory by providing a special [truncated]
The CVE-2026-14664 vulnerability is a heap buffer overflow in PostgreSQL regexp that allows query authors to execute arbitrary code as the operating system user running the database. This issue is related to CVE-2026-2006 but involves unanticipated data growth when round-tripped through pg_wchar. Affected versions include PostgreSQL before 18.6, 17.11, 16.15, 15.19, and 14.24. The vulnerability has a CVSS [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T13:17:43.700Z and has not been modified since then. The NVD entry is currently Modified. The CVE-2026-14663 vulnerability involves cleartext storage in PostgreSQL pgcrypto disabled ciphers. An attacker can recover cleartext via direct observation of the faulty ciphertext. The OpenSSL version and [truncated]
The CVE-2026-14662 vulnerability is an integer wraparound issue in PostgreSQL tsvector and tsquery data type functions. This problem allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs, potentially leading to arbitrary code execution as the operating system user running the database. The vulnerability is typically sourced fr [truncated]
A SQL injection vulnerability in PostgreSQL's logical replication feature allows a malicious subscriber table creator to execute arbitrary SQL with the publication-side credentials. The attack vector involves the ALTER SUBSCRIPTION ... REFRESH PUBLICATION command, which triggers the injection at the next REFRESH PUBLICATION execution. This vulnerability affects PostgreSQL versions 16.0 through 16.13, 17.0 [truncated]
CVE-2026-6637 is a high-severity PostgreSQL vulnerability in the refint module. The CVE description says a stack buffer overflow can let an unprivileged database user execute arbitrary code as the operating system user running PostgreSQL. It also notes a separate attack path involving applications that expose user-controlled primary-key updates through refint cascade behavior, where SQL injection could al [truncated]
A buffer over-read vulnerability exists in PostgreSQL's pg_restore_attribute_stats() function, affecting versions 18.0 through 18.3. The function accepts array values with mismatched lengths, causing query planning operations to read beyond the bounds of one array. This allows a table maintainer with appropriate privileges to infer memory contents past the array boundary. The vulnerability is confined to [truncated]
## Summary PostgreSQL versions prior to 18.4, 17.10, 16.14, 15.18, and 14.23 contain an uncontrolled recursion vulnerability in SSL and GSS negotiation code. An attacker with connectivity to a PostgreSQL AF_UNIX socket can trigger sustained denial of service. If both SSL and GSS are disabled, the attack surface extends to TCP sockets. The vulnerability was published on 2026-05-14 and last modified on 2026 [truncated]
A covert timing channel vulnerability exists in PostgreSQL's MD5 password authentication comparison. The flaw allows network-based attackers to recover user credentials through timing analysis of authentication responses. This affects databases with legacy MD5-hashed passwords, typically originating from upgrades from PostgreSQL 13 or earlier, while scram-sha-256 passwords (the current default) are not vu [truncated]
CVE-2026-6477 is a high-severity PostgreSQL client-library issue in libpq where inherently dangerous PQfn(..., result_is_int=0, ...) usage can let a PostgreSQL server superuser write an arbitrarily large server-controlled response into a client stack buffer. The affected paths include lo_export(), lo_read(), lo_lseek64(), and lo_tell64(), and the impact extends to psql and pg_dump because they call lo_rea [truncated]
A SQL injection vulnerability in PostgreSQL's pg_createsubscriber function allows authenticated attackers with pg_create_subscription rights to execute arbitrary SQL commands with superuser privileges. The vulnerability affects PostgreSQL versions 17.0 through 17.9 and 18.0 through 18.3; versions prior to 17.0 are unaffected. The attack vector requires network access and low attack complexity, but high pr [truncated]
CVE-2026-6475 is a PostgreSQL file-overwrite issue in pg_basebackup plain format and pg_rewind caused by symlink following. The vendor notes that an origin superuser can overwrite local files such as a user’s .bashrc, which can affect the operating system account. PostgreSQL also notes an important practical limitation: if the server is started normally after these commands, it implicitly trusts the origi [truncated]
CVE-2026-6474 is a PostgreSQL format-string vulnerability in timeofday() that can disclose portions of server memory when crafted timezone zone values are processed. The issue is publicly documented as medium severity and affects PostgreSQL versions before 18.4, 17.10, 16.14, 15.18, and 14.23.