Skip to main content

Vendor archive

postgresql CVEs

Beta · best-effort

192 CVEs tagged to vendor postgresql14 Critical, 80 High, 85 Medium, 13 Low, 0 Unrated.

CVE-2026-54291

Published Jul 6, 2026

pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with cha…

CVSS 8.2 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-6638

Published May 14, 2026

SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publi…

CVSS 3.7 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-6637

Published May 14, 2026

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct a…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-6575

Published May 14, 2026

Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which causes query planning to read past end of one array. This all…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-6479

Published May 14, 2026

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-6478

Published May 14, 2026

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not a…

CVSS 6.5 · Medium
evidence mentions
38
Buzz score
48.0
Vendor/product tagsBeta · best-effort

CVE-2026-6477

Published May 14, 2026

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuse…

CVSS 8.8 · High
evidence mentions
45
Buzz score
48.0
Vendor/product tagsBeta · best-effort

CVE-2026-6476

Published May 14, 2026

SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser. The attack takes effect when pg_cre…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-6475

Published May 14, 2026

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the op…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-6474

Published May 14, 2026

Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before Postg…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-6473

Published May 14, 2026

Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may ex…

CVSS 8.8 · High
evidence mentions
38
Buzz score
48.0
Vendor/product tagsBeta · best-effort

CVE-2026-6472

Published May 14, 2026

Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-42198

Published Apr 29, 2026

pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authen…

CVSS 7.5 · High
evidence mentions
13
Buzz score
39.4
Vendor/product tagsBeta · best-effort

CVE-2026-2007

Published Feb 12, 2026

Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns t…

CVSS 8.2 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-2006

Published Feb 12, 2026

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to e…

CVSS 8.8 · High
evidence mentions
36
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2026-2005

Published Feb 12, 2026

Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 1…

CVSS 8.8 · High
evidence mentions
35
Buzz score
48.0
Vendor/product tagsBeta · best-effort

CVE-2026-2004

Published Feb 12, 2026

Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user…

CVSS 8.8 · High
evidence mentions
34
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2026-2003

Published Feb 12, 2026

Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-49146

Published Jun 11, 2025

pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is…

CVSS 8.2 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2024-10979

Published Nov 14, 2024

Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often su…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10977

Published Nov 14, 2024

Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For ex…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-10976

Published Nov 14, 2024

Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed mo…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7348

Published Aug 8, 2024

Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4317

Published May 14, 2024

Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CR…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 192 CVEsPage 1 of 8