CVEs we hold for Postgresql
Records whose assigning authority named Postgresql as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-6575PostgreSQL pg_restore_attribute_stats accepts values that cause query planning to read past end of stats arrayn/a PostgreSQL
CVE-2026-6479PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursionn/a PostgreSQL
CVE-2026-6477PostgreSQL libpq lo_* functions let server superuser overwrite client stack memoryn/a PostgreSQL
CVE-2026-6476PostgreSQL pg_createsubscriber allows SQL injection via subscription namen/a PostgreSQL
CVE-2026-6475PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choicen/a PostgreSQL
CVE-2026-6464PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commandsn/a PostgreSQL
CVE-2026-2007PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memoryn/a PostgreSQL
CVE-2026-2006PostgreSQL missing validation of multibyte character length executes arbitrary coden/a PostgreSQL
CVE-2026-2004PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary coden/a PostgreSQL
CVE-2026-18408PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql clientn/a PostgreSQL
CVE-2026-16239PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary coden/a PostgreSQL
CVE-2026-16238PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary coden/a PostgreSQL
CVE-2026-15742PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparoundn/a PostgreSQL
CVE-2026-14681PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSLn/a PostgreSQL
CVE-2026-14679PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memoryn/a PostgreSQL
CVE-2026-14677PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparoundn/a PostgreSQL
CVE-2026-14676PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary coden/a PostgreSQL
CVE-2026-14672PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oraclen/a PostgreSQL
CVE-2026-14670PostgreSQL plperl tied object heap buffer overflow executes arbitrary coden/a PostgreSQL
CVE-2026-14668PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary readn/a PostgreSQL
CVE-2026-14663PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartextn/a PostgreSQL
CVE-2026-14662PostgreSQL tsvector and tsquery undersize allocations, via integer wraparoundn/a PostgreSQL
CVE-2025-8715PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target servern/a PostgreSQL
CVE-2025-8714PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql clientn/a PostgreSQL
CVE-2025-8713PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child tablen/a PostgreSQL
CVE-2025-4207PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validationn/a PostgreSQL
CVE-2025-1094PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validationn/a PostgreSQL
CVE-2024-10976PostgreSQL row security below e.g. subqueries disregards user ID changesn/a PostgreSQL
CVE-2024-0985PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQLn/a PostgreSQL
100 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.