Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

postgresql — Vulnerabilities & Security Advisories 111

All 111 CVE vulnerabilities found in postgresql, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the PostgreSQL open-source database product. It collects reported flaws spanning the last several years, including memory corruption, input validation errors, and privilege escalation issues. Readers can use this view to track the project's advisory history, analyze recurring weakness classes like buffer overflows or SQL injection, and understand the overall security posture of the PostgreSQL codebase over time.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-6637 PostgreSQL refint allows stack buffer overflow and SQL injection CWE-121 8.8 High 2026-05-14
CVE-2026-6479 PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion CWE-674 7.5 High 2026-05-14
CVE-2026-6478 PostgreSQL discloses MD5-hashed passwords via covert timing channel CWE-385 6.5 Medium 2026-05-14
CVE-2026-6476 PostgreSQL pg_createsubscriber allows SQL injection via subscription name CWE-89 7.2 High 2026-05-14
CVE-2026-6477 PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory CWE-242 8.8 High 2026-05-14
CVE-2026-6475 PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice CWE-61 8.8 High 2026-05-14
CVE-2026-6474 PostgreSQL timeofday() can disclose portions of server memory CWE-134 4.3 Medium 2026-05-14
CVE-2026-6473 PostgreSQL server undersizes allocations, via integer wraparound CWE-190 8.8 High 2026-05-14
CVE-2026-6472 PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege CWE-862 5.4 Medium 2026-05-14
CVE-2026-2007 PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory CWE-122 8.2 High 2026-02-12
CVE-2026-2005 PostgreSQL pgcrypto heap buffer overflow executes arbitrary code CWE-122 8.8 High 2026-02-12
CVE-2026-2006 PostgreSQL missing validation of multibyte character length executes arbitrary code CWE-129 8.8 High 2026-02-12
CVE-2026-2004 PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code CWE-1287 8.8 High 2026-02-12
CVE-2026-2003 PostgreSQL oidvector discloses a few bytes of memory CWE-1287 4.3 Medium 2026-02-12
CVE-2025-12818 PostgreSQL libpq undersizes allocations, via integer wraparound CWE-190 5.9 Medium 2025-11-13
CVE-2025-12817 PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege CWE-862 3.1 Low 2025-11-13
CVE-2025-8715 PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server CWE-93 8.8 High 2025-08-14
CVE-2025-8714 PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client CWE-829 8.8 High 2025-08-14
CVE-2025-8713 PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table CWE-1230 3.1 Low 2025-08-14
CVE-2025-4207 PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation CWE-126 5.9 Medium 2025-05-08
CVE-2025-1094 PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation CWE-149 8.1 High 2025-02-13
CVE-2024-10979 PostgreSQL PL/Perl environment variable changes execute arbitrary code CWE-15 8.8 High 2024-11-14
CVE-2024-10978 PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID CWE-266 4.2 Medium 2024-11-14
CVE-2024-10977 PostgreSQL libpq retains an error message from man-in-the-middle CWE-348 3.1 Low 2024-11-14
CVE-2024-10976 PostgreSQL row security below e.g. subqueries disregards user ID changes CWE-1250 4.2 Medium 2024-11-14
CVE-2024-7348 PostgreSQL relation replacement during pg_dump executes arbitrary SQL CWE-367 8.8 High 2024-08-08
CVE-2024-4317 PostgreSQL pg_stats_ext and pg_stats_ext_exprs lack authorization checks CWE-862 3.1 Low 2024-05-09
CVE-2024-0985 PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL CWE-271 8.0 High 2024-02-08
CVE-2023-2455 PostgreSQL 安全漏洞 CWE-20 9.1 - 2023-06-09
CVE-2023-2454 PostgreSQL 安全漏洞 CWE-20 6.7 - 2023-06-09

All 111 known CVE vulnerabilities affecting postgresql with full Chinese analysis, references, and POCs where available.