postgresql
32 known vulnerabilities affecting postgresql products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-42198 | Medium | 3.3% | 7.5 | pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before v… | |
| CVE-2026-6473 | Medium | 1.0% | 8.8 | Integer wraparound in multiple PostgreSQL server features allows an unprivileged… | |
| CVE-2026-14669 | Medium | 0.7% | 8.8 | Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosin… | |
| CVE-2026-16239 | Medium | 0.5% | 8.8 | Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute … | |
| CVE-2026-14662 | Medium | 0.5% | 8.8 | Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows… | |
| CVE-2026-6477 | Medium | 0.5% | 8.8 | Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreS… | |
| CVE-2026-14664 | Medium | 0.4% | 8.8 | Heap buffer overflow in PostgreSQL regexp allows the query author to execute arb… | |
| CVE-2026-14670 | Medium | 0.4% | 8.8 | Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the funct… | |
| CVE-2026-15742 | Medium | 0.4% | 8.8 | Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to… | |
| CVE-2026-14676 | Medium | 0.4% | 8.8 | Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to… | |
| CVE-2026-19385 | Medium | 0.4% | 8.8 | Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allo… | |
| CVE-2026-14671 | Medium | 0.4% | 8.8 | Type confusion in PostgreSQL module "refint" allows an object creator to execute… | |
| CVE-2026-14677 | Medium | 0.4% | 8.8 | Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an obj… | |
| CVE-2026-14680 | Medium | 0.4% | 8.8 | Type confusion with PostgreSQL "internal" data type arguments allows any user to… | |
| CVE-2026-16238 | Medium | 0.4% | 8.8 | Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creat… | |
| CVE-2026-18408 | Medium | 0.4% | 8.8 | Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser o… | |
| CVE-2026-6464 | Medium | 0.4% | 8.1 | Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrato… | |
| CVE-2026-15741 | Medium | 0.3% | 8.8 | SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute … | |
| CVE-2026-14668 | Medium | 0.3% | 8.1 | Type confusion regarding input of PostgreSQL ctid data type selectivity estimato… | |
| CVE-2026-14679 | Medium | 0.3% | 8.2 | Stack buffer overflow in PostgreSQL argument name matching allows an object crea… | |
| CVE-2026-6471 | Medium | 0.3% | 7.2 | Missing authorization in PostgreSQL logical decoding allows a non-superuser hold… | |
| CVE-2026-6478 | Low | 0.6% | 6.5 | Covert timing channel in comparison of MD5-hashed password in PostgreSQL authent… | |
| CVE-2026-14672 | Low | 0.3% | 5.3 | Observable response discrepancy in PostgreSQL SCRAM authentication allows an una… | |
| CVE-2026-16241 | Low | 0.2% | 3.8 | Integer underflow in PostgreSQL ECPG allows a database server administrator to a… | |
| CVE-2026-14678 | Low | 0.2% | 4.3 | Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end o… | |
| CVE-2026-18024 | Low | 0.2% | 4.3 | Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up… | |
| CVE-2026-6470 | Low | 0.2% | 4.3 | Missing authorization in PostgreSQL DDL commands allows an object creator to ach… | |
| CVE-2026-6469 | Low | 0.2% | 3.8 | Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reas… | |
| CVE-2026-14666 | Low | 0.2% | 4.2 | Incomplete tracking in PostgreSQL of changes to role membership, role attributes… | |
| CVE-2026-14673 | Low | 0.2% | 3.8 | Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function… | |
| CVE-2026-14663 | Low | 0.1% | 6.5 | Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recov… | |
| CVE-2026-14681 | Low | 0.1% | 4.2 | Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a … |