CVE-2016-7048: PostgreSQL

High severity, CVSS 8.1. EPSS: 4.9% chance of exploitation in the next 30 days.

The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary code by leveraging use of HTTP to download software.

Affected products

  • PostgreSQL PostgreSQL: before 9.1.24 (fixed in 9.1.24); from 9.2, before 9.2.19 (fixed in 9.2.19); from 9.3, before 9.3.15 (fixed in 9.3.15); from 9.4.0, before 9.4.10 (fixed in 9.4.10); from 9.5.0, before 9.5.5 (fixed in 9.5.5)

Published 2018-08-20. Last modified 2026-06-17.