PostgreSQL oidvector discloses a few bytes of memory
Published Feb 12, 2026
4.3
MEDIUMCVSS 3.1
EPSS 0.29%
Description
Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Affected products
- Vendor n/a Product PostgreSQL Defaultunaffected
- Version 0StatusaffectedConstraints<14.21
- Version 15StatusaffectedConstraints<15.16
- Version 16StatusaffectedConstraints<16.12
- Version 17StatusaffectedConstraints<17.8
- Version 18StatusaffectedConstraints<18.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | PostgreSQL | unaffected |
|
- ≥ 14.0 · < 14.21
- ≥ 15.0 · < 15.16
- ≥ 16.0 · < 16.12
- ≥ 17.0 · < 17.8
- ≥ 18.0 · < 18.2
No data.
Red Hat Enterprise Linux 10
postgresql16-0:16.13-1.el10_1
Fixed · RHSA-2026:3887
Red Hat Enterprise Linux 10
postgresql16-0:16.13-1.el10_2
Fixed · RHSA-2026:19010
Red Hat Enterprise Linux 10
postgresql18-0:18.3-1.el10_2
Fixed · RHSA-2026:19009
Red Hat Enterprise Linux 10.0 Extended Update Support
postgresql16-0:16.13-1.el10_0
Fixed · RHSA-2026:4441
Red Hat Enterprise Linux 8
postgresql:15-8100020260227221316.489197e6
Fixed · RHSA-2026:4059
Red Hat Enterprise Linux 8
postgresql:16-8100020260227221401.489197e6
Fixed · RHSA-2026:4063
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
postgresql:15-8080020260306092921.63b34585
Fixed · RHSA-2026:4515
Red Hat Enterprise Linux 9
postgresql-0:13.23-2.el9_7
Fixed · RHSA-2026:3730
Red Hat Enterprise Linux 9
postgresql:15-9070020260227094950.rhel9
Fixed · RHSA-2026:3896
Red Hat Enterprise Linux 9
postgresql:16-9070020260227095951.rhel9
Fixed · RHSA-2026:4110
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
postgresql:15-9020020260309133405.rhel9
Fixed · RHSA-2026:4254
Red Hat Enterprise Linux 9.4 Extended Update Support
postgresql:15-9040020260305163703.rhel9
Fixed · RHSA-2026:4548
Red Hat Enterprise Linux 9.4 Extended Update Support
postgresql:16-9040020260306102041.rhel9
Fixed · RHSA-2026:4544
Red Hat Enterprise Linux 9.6 Extended Update Support
postgresql:15-9060020260309125703.rhel9
Fixed · RHSA-2026:4546
Red Hat Enterprise Linux 9.6 Extended Update Support
postgresql:16-9060020260305153549.rhel9
Fixed · RHSA-2026:4547
Red Hat Hardened Images
postgresql18-main-18.3-1.2.hum1
Fixed · RHSA-2026:8756
Red Hat Update Infrastructure 5
rhui5/rhua-rhel9:1773670137
Fixed · RHSA-2026:4943
Red Hat Enterprise Linux 6
postgresql
Fix deferred
Red Hat Enterprise Linux 7
postgresql
Fix deferred
Red Hat Enterprise Linux 8
postgresql:12/postgresql
Fix deferred
Red Hat Enterprise Linux 8
postgresql:13/postgresql
Fix deferred
Red Hat Enterprise Linux 9
postgresql:18/postgresql
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | postgresql16-0:16.13-1.el10_1 | Fixed | RHSA-2026:3887 |
| Red Hat Enterprise Linux 10 | postgresql16-0:16.13-1.el10_2 | Fixed | RHSA-2026:19010 |
| Red Hat Enterprise Linux 10 | postgresql18-0:18.3-1.el10_2 | Fixed | RHSA-2026:19009 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | postgresql16-0:16.13-1.el10_0 | Fixed | RHSA-2026:4441 |
| Red Hat Enterprise Linux 8 | postgresql:15-8100020260227221316.489197e6 | Fixed | RHSA-2026:4059 |
| Red Hat Enterprise Linux 8 | postgresql:16-8100020260227221401.489197e6 | Fixed | RHSA-2026:4063 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | postgresql:15-8080020260306092921.63b34585 | Fixed | RHSA-2026:4515 |
| Red Hat Enterprise Linux 9 | postgresql-0:13.23-2.el9_7 | Fixed | RHSA-2026:3730 |
| Red Hat Enterprise Linux 9 | postgresql:15-9070020260227094950.rhel9 | Fixed | RHSA-2026:3896 |
| Red Hat Enterprise Linux 9 | postgresql:16-9070020260227095951.rhel9 | Fixed | RHSA-2026:4110 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | postgresql:15-9020020260309133405.rhel9 | Fixed | RHSA-2026:4254 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | postgresql:15-9040020260305163703.rhel9 | Fixed | RHSA-2026:4548 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | postgresql:16-9040020260306102041.rhel9 | Fixed | RHSA-2026:4544 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | postgresql:15-9060020260309125703.rhel9 | Fixed | RHSA-2026:4546 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | postgresql:16-9060020260305153549.rhel9 | Fixed | RHSA-2026:4547 |
| Red Hat Hardened Images | postgresql18-main-18.3-1.2.hum1 | Fixed | RHSA-2026:8756 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-rhel9:1773670137 | Fixed | RHSA-2026:4943 |
| Red Hat Enterprise Linux 6 | postgresql | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | postgresql | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | postgresql:12/postgresql | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | postgresql:13/postgresql | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | postgresql:18/postgresql | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Feb 12, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Feb–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.29% (0.00292) | 19.63th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.28% (0.00281) | 19.59th | v5 (v2026.06.15) |
| Feb 13, 2026 | 0.04% (0.00040) | 12.07th | v4 (v2025.03.14) |
References (5)
- https://access.redhat.com/security/cve/CVE-2026-2003 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2439322 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-2003
- https://www.cve.org/CVERecord?id=CVE-2026-2003
- https://www.postgresql.org/support/security/CVE-2026-2003/ Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-2003 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2439322 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-2003 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-2003 | ||
| https://www.postgresql.org/support/security/CVE-2026-2003/ | Vendor Advisory |
Change history (0)
No recorded changes yet.