PostgreSQL / PostgreSQL
204 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-14671 | PostgreSQL refint plan cache type confusion executes arbitrary code | HIGH | 8.8 | Aug 13, 2026 |
| CVE-2026-6471 | PostgreSQL logical decoding can dlopen arbitrary file | HIGH | 7.2 | Aug 13, 2026 |
| CVE-2026-6470 | PostgreSQL fails to check type USAGE privilege | MEDIUM | 4.3 | Aug 13, 2026 |
| CVE-2026-6469 | PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership | LOW | 3.8 | Aug 13, 2026 |
| CVE-2026-6464 | PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands | HIGH | 8.1 | Aug 13, 2026 |
| CVE-2026-19385 | PostgreSQL pg_dump heap buffer overflow executes arbitrary code | HIGH | 8.8 | Aug 13, 2026 |
| CVE-2026-18408 | PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client | HIGH | 8.8 | Aug 13, 2026 |
| CVE-2026-18024 | PostgreSQL ascii() function reads past end of buffer | MEDIUM | 4.3 | Aug 13, 2026 |
| CVE-2026-16241 | PostgreSQL ECPG integer underflow can crash the client | LOW | 3.8 | Aug 13, 2026 |
| CVE-2026-16239 | PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code | HIGH | 8.8 | Aug 13, 2026 |
| CVE-2026-16238 | PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code | HIGH | 8.8 | Aug 13, 2026 |
| CVE-2026-15742 | PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound | HIGH | 8.8 | Aug 13, 2026 |
| CVE-2026-15741 | PostgreSQL expression deparse allows SQL injection via EXTRACT argument | HIGH | 8.8 | Aug 13, 2026 |
| CVE-2026-14681 | PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL | MEDIUM | 4.2 | Aug 13, 2026 |
| CVE-2026-14680 | PostgreSQL type confusion via "internal" arguments | HIGH | 8.8 | Aug 13, 2026 |
| CVE-2026-14679 | PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory | HIGH | 8.2 | Aug 13, 2026 |
| CVE-2026-14678 | PostgreSQL pg_trgm picksplit reads past end of buffer | MEDIUM | 4.3 | Aug 13, 2026 |
| CVE-2026-14677 | PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound | HIGH | 8.8 | Aug 13, 2026 |
| CVE-2026-14676 | PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code | HIGH | 8.8 | Aug 13, 2026 |
| CVE-2026-14673 | PostgreSQL amcheck does not clear untrusted search path | LOW | 3.8 | Aug 13, 2026 |
| CVE-2026-14672 | PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle | MEDIUM | 5.3 | Aug 13, 2026 |
| CVE-2026-14670 | PostgreSQL plperl tied object heap buffer overflow executes arbitrary code | HIGH | 8.8 | Aug 13, 2026 |
| CVE-2026-14669 | PostgreSQL to_char heap buffer overflow executes arbitrary code | HIGH | 8.8 | Aug 13, 2026 |
| CVE-2026-14668 | PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read | HIGH | 8.1 | Aug 13, 2026 |
| CVE-2026-14666 | PostgreSQL row security caching disregards role modifications | MEDIUM | 4.2 | Aug 13, 2026 |
Showing 1 to 25 of 204 CVEs