Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-90775— PostGIS address_standardizer through 3.7.0 Out-of-Bounds Read via Unvalidated Rule Weight

Quick assessment

Affected
PostGIS address_standardizer
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

PostGIS address_standardizer 在 3.7.0 及之前的版本中,未对调用方提供的规则表中的 Weight 参数进行有效验证,就直接将其用作数组索引。攻击者可以构造带有越界 Weight 值的恶意规则行,从而触发 load_value 数组的越界读取,导致 PostgreSQL 后端进程崩溃并终止所有集群会话。

CVSS 6.5 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-90775

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
PostGIS address_standardizer through 3.7.0 Out-of-Bounds Read via Unvalidated Rule Weight
Source: CVE Program / CVE List V5
Vulnerability Description
PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, causing the PostgreSQL backend process to crash and terminate all cluster sessions.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
PostGIS address_standardizer 0 ~ 3.7.0 -

II. Public POCs for CVE-2026-90775

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-90775

登录查看更多情报信息。

Other References for CVE-2026-90775 (8)

IV. Related Vulnerabilities

V. Comments for CVE-2026-90775

No comments yet


Leave a comment