PatchSiren

PostgreSQL CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Postgresql CVE published 2026-05-14

CVE-2026-6473

CVE-2026-6473 is a high-severity PostgreSQL server vulnerability caused by integer wraparound in multiple server features. An unprivileged database user may be able to trigger an undersized allocation followed by an out-of-bounds write. Depending on the affected path and deployment, this can lead to arbitrary code execution as the operating system user running PostgreSQL. The NVD record also notes that in [truncated]

MEDIUM PostgreSQL CVE published 2026-05-14

CVE-2026-6472

A missing authorization vulnerability in PostgreSQL's CREATE TYPE implementation allows an authenticated attacker with object creation privileges to hijack queries that rely on search_path resolution for user-defined types. When a victim query executes, it may inadvertently invoke attacker-controlled SQL functions instead of intended extension-defined or legitimate user-defined types. This represents a pr [truncated]

HIGH PostgreSQL CVE published 2026-02-12

CVE-2026-2007

CVE-2026-2007 is a heap buffer overflow vulnerability in the PostgreSQL pg_trgm module. An attacker with database user privileges can exploit this vulnerability by providing a crafted input string, potentially leading to unknown impacts, including possible privilege escalation. The vulnerability affects PostgreSQL versions 18.0 and 18.1. The CVSS score for this vulnerability is 8.2, indicating a high seve [truncated]

HIGH PostgreSQL CVE published 2026-02-12

CVE-2026-2006

CVE-2026-2006 is a high-severity vulnerability in PostgreSQL that allows a database user to execute arbitrary code as the operating system user running the database. The vulnerability is caused by a missing validation of multibyte character length in PostgreSQL text manipulation, which can lead to a buffer overrun. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected. This vulnerabi [truncated]

HIGH PostgreSQL CVE published 2026-02-12

CVE-2026-2005

CVE-2026-2005 is a heap buffer overflow vulnerability in the pgcrypto module of PostgreSQL. This vulnerability allows a ciphertext provider to execute arbitrary code as the operating system user running the database. The affected versions include PostgreSQL 14.0 to 14.21, 15.0 to 15.16, 16.0 to 16.12, 17.0 to 17.8, and 18.0 to 18.2. To exploit this vulnerability, an attacker would need to have legitimate [truncated]