PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
Published Feb 12, 2026
8.2
HIGHCVSS 3.1
EPSS 0.50%
Description
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.
Affected products
- Vendor n/a Product PostgreSQL Defaultunaffected
- Version 18StatusaffectedConstraints<18.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | PostgreSQL | unaffected |
|
- ≥ 18.0 · < 18.2
No data.
Red Hat Enterprise Linux 10
postgresql18-0:18.3-1.el10_2
Fixed · RHSA-2026:19009
Red Hat Hardened Images
postgresql18-main-18.3-1.2.hum1
Fixed · RHSA-2026:8756
Red Hat Enterprise Linux 9
postgresql18
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | postgresql18-0:18.3-1.el10_2 | Fixed | RHSA-2026:19009 |
| Red Hat Hardened Images | postgresql18-main-18.3-1.2.hum1 | Fixed | RHSA-2026:8756 |
| Red Hat Enterprise Linux 9 | postgresql18 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Feb 12, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Feb–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.50% (0.00499) | 40.52th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.34% (0.00335) | 25.12th | v5 (v2026.06.15) |
| Feb 13, 2026 | 0.04% (0.00040) | 11.92th | v4 (v2025.03.14) |
References (8)
- https://access.redhat.com/errata/RHSA-2026:19009
- https://access.redhat.com/errata/RHSA-2026:8756
- https://access.redhat.com/security/cve/CVE-2026-2007 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2439320 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-2007
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2007.json
- https://www.cve.org/CVERecord?id=CVE-2026-2007
- https://www.postgresql.org/support/security/CVE-2026-2007/ Vendor Advisory
Change history (0)
No recorded changes yet.