Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

postgresql — Vulnerabilities & Security Advisories 111

All 111 CVE vulnerabilities found in postgresql, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the PostgreSQL open-source database product. It collects reported flaws spanning the last several years, including memory corruption, input validation errors, and privilege escalation issues. Readers can use this view to track the project's advisory history, analyze recurring weakness classes like buffer overflows or SQL injection, and understand the overall security posture of the PostgreSQL codebase over time.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-14671 PostgreSQL refint plan cache type confusion executes arbitrary code CWE-843 8.8 High 2026-08-13
CVE-2026-6471 PostgreSQL logical decoding can dlopen arbitrary file CWE-862 7.2 High 2026-08-13
CVE-2026-6470 PostgreSQL fails to check type USAGE privilege CWE-862 4.3 Medium 2026-08-13
CVE-2026-6469 PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership CWE-708 3.8 Low 2026-08-13
CVE-2026-6464 PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands CWE-829 8.1 High 2026-08-13
CVE-2026-18408 PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client CWE-829 8.8 High 2026-08-13
CVE-2026-19385 PostgreSQL pg_dump heap buffer overflow executes arbitrary code CWE-122 8.8 High 2026-08-13
CVE-2026-16241 PostgreSQL ECPG integer underflow can crash the client CWE-191 3.8 Low 2026-08-13
CVE-2026-18024 PostgreSQL ascii() function reads past end of buffer CWE-126 4.3 Medium 2026-08-13
CVE-2026-16239 PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code CWE-843 8.8 High 2026-08-13
CVE-2026-15742 PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound CWE-190 8.8 High 2026-08-13
CVE-2026-16238 PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code CWE-843 8.8 High 2026-08-13
CVE-2026-15741 PostgreSQL expression deparse allows SQL injection via EXTRACT argument CWE-89 8.8 High 2026-08-13
CVE-2026-14681 PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL CWE-924 4.2 Medium 2026-08-13
CVE-2026-14680 PostgreSQL type confusion via "internal" arguments CWE-843 8.8 High 2026-08-13
CVE-2026-14678 PostgreSQL pg_trgm picksplit reads past end of buffer CWE-126 4.3 Medium 2026-08-13
CVE-2026-14679 PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory CWE-121 8.2 High 2026-08-13
CVE-2026-14677 PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound CWE-190 8.8 High 2026-08-13
CVE-2026-14673 PostgreSQL amcheck does not clear untrusted search path CWE-426 3.8 Low 2026-08-13
CVE-2026-14676 PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code CWE-122 8.8 High 2026-08-13
CVE-2026-14672 PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle CWE-204 5.3 Medium 2026-08-13
CVE-2026-14670 PostgreSQL plperl tied object heap buffer overflow executes arbitrary code CWE-122 8.8 High 2026-08-13
CVE-2026-14669 PostgreSQL to_char heap buffer overflow executes arbitrary code CWE-122 8.8 High 2026-08-13
CVE-2026-14668 PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read CWE-843 8.1 High 2026-08-13
CVE-2026-14666 PostgreSQL row security caching disregards role modifications CWE-1250 4.2 Medium 2026-08-13
CVE-2026-14664 PostgreSQL regexp heap buffer overflow executes arbitrary code CWE-122 8.8 High 2026-08-13
CVE-2026-14663 PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext CWE-313 6.5 Medium 2026-08-13
CVE-2026-14662 PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound CWE-190 8.8 High 2026-08-13
CVE-2026-6638 PostgreSQL REFRESH PUBLICATION allows SQL injection via table name CWE-89 3.7 Low 2026-05-14
CVE-2026-6575 PostgreSQL pg_restore_attribute_stats accepts values that cause query planning to read past end of stats array CWE-126 4.3 Medium 2026-05-14

All 111 known CVE vulnerabilities affecting postgresql with full Chinese analysis, references, and POCs where available.