PostgreSQL — свободная объектно-реляционная система управления базами данных.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 017
SUSE-SU-2026:0787-1
Security update for postgresql17
SUSE-SU-2026:0785-1
Security update for postgresql18
SUSE-SU-2026:0784-1
Security update for postgresql16
SUSE-SU-2026:0769-1
Security update for postgresql18
GHSA-qw3h-8vxv-jf6c
Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
GHSA-f3vj-j2m6-8hfj
Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
GHSA-hgmp-6hmc-prfc
Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
GHSA-5pr9-9395-q5gq
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.
GHSA-mq5v-x68w-mc4f
Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
CVE-2026-2007
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to a ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
SUSE-SU-2026:0787-1 Security update for postgresql17 | 0% Низкий | 22 дня назад | ||
SUSE-SU-2026:0785-1 Security update for postgresql18 | 0% Низкий | 22 дня назад | ||
SUSE-SU-2026:0784-1 Security update for postgresql16 | 0% Низкий | 22 дня назад | ||
SUSE-SU-2026:0769-1 Security update for postgresql18 | 0% Низкий | 22 дня назад | ||
GHSA-qw3h-8vxv-jf6c Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected. | CVSS3: 8.8 | 0% Низкий | около 1 месяца назад | |
GHSA-f3vj-j2m6-8hfj Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected. | CVSS3: 4.3 | 0% Низкий | около 1 месяца назад | |
GHSA-hgmp-6hmc-prfc Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected. | CVSS3: 8.8 | 0% Низкий | около 1 месяца назад | |
GHSA-5pr9-9395-q5gq Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected. | CVSS3: 8.2 | 0% Низкий | около 1 месяца назад | |
GHSA-mq5v-x68w-mc4f Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected. | CVSS3: 8.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-2007 Heap buffer overflow in PostgreSQL pg_trgm allows a database user to a ... | CVSS3: 8.2 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу