Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PostgreSQL

PostgreSQLсвободная объектно-реляционная система управления базами данных.

Релизный цикл, информация об уязвимостях

Продукт: PostgreSQL
Вендор: PostgreSQL

График релизов

141516171820212022202320242025202620272028202920302031

Релизные элементы

KBВерсияБилдДата доступности
17.1117.11
17.1017.10
17.917.9
17.817.8
17.717.7
17.617.6
17.517.5
17.417.4
17.317.3
17.217.2

Показывать по

Недавние уязвимости PostgreSQL

Количество 1 300

debian логотип

CVE-2026-16239

около 1 месяца назад

Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user t ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-16239

около 1 месяца назад

Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2026-16238

около 1 месяца назад

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an ob ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-16238

около 1 месяца назад

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2026-15742

около 1 месяца назад

Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-15742

около 1 месяца назад

Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2026-15741

около 1 месяца назад

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner t ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-15741

около 1 месяца назад

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2026-14681

около 1 месяца назад

Improper enforcement of message integrity in PostgreSQL GSSAPI support ...

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2026-14681

около 1 месяца назад

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

CVSS3: 4.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2026-16239

Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user t ...

CVSS3: 8.8
1%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-16239

Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.8
1%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-16238

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an ob ...

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-16238

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-15742

Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct ...

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-15742

Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-15741

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner t ...

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-15741

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-14681

Improper enforcement of message integrity in PostgreSQL GSSAPI support ...

CVSS3: 4.2
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-14681

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

CVSS3: 4.2
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу


Поделиться