CVE-2026-14671
- EPSS 0.41%
- Veröffentlicht 13.08.2026 13:17:44
- Zuletzt bearbeitet 19.08.2026 14:57:40
Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with s...
CVE-2026-14672
- EPSS 0.39%
- Veröffentlicht 13.08.2026 13:17:44
- Zuletzt bearbeitet 19.08.2026 14:57:53
Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, be...
CVE-2026-14673
- EPSS 0.27%
- Veröffentlicht 13.08.2026 13:17:44
- Zuletzt bearbeitet 19.08.2026 01:14:45
Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the...
CVE-2026-14676
- EPSS 0.61%
- Veröffentlicht 13.08.2026 13:17:44
- Zuletzt bearbeitet 19.08.2026 01:14:14
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before...
CVE-2026-14662
- EPSS 0.67%
- Veröffentlicht 13.08.2026 13:17:43
- Zuletzt bearbeitet 19.08.2026 14:54:41
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the o...
CVE-2026-14663
- EPSS 0.11%
- Veröffentlicht 13.08.2026 13:17:43
- Zuletzt bearbeitet 19.08.2026 14:54:59
Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts ...
CVE-2026-14664
- EPSS 0.61%
- Veröffentlicht 13.08.2026 13:17:43
- Zuletzt bearbeitet 19.08.2026 14:55:12
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case i...
CVE-2026-14666
- EPSS 0.21%
- Veröffentlicht 13.08.2026 13:17:43
- Zuletzt bearbeitet 19.08.2026 14:56:26
Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale polici...
CVE-2026-9617
- EPSS 0.25%
- Veröffentlicht 27.05.2026 13:55:10
- Zuletzt bearbeitet 02.06.2026 00:40:18
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and placing malicious code inside a column identifier. If a superuser calls the k-anonymity function, the malicious code is executed wi...
CVE-2026-6637
- EPSS 0.38%
- Veröffentlicht 14.05.2026 13:00:15
- Zuletzt bearbeitet 18.05.2026 15:05:21
Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column ...