CVE-2019-10211: PostgreSQL

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory.

Affected products

  • PostgreSQL PostgreSQL: before 9.4.24 (fixed in 9.4.24); from 9.5.0, before 9.5.19 (fixed in 9.5.19); from 9.6.0, before 9.6.15 (fixed in 9.6.15); from 10.0, before 10.10 (fixed in 10.10); from 11.0, before 11.5 (fixed in 11.5)

Published 2019-10-29. Last modified 2026-06-17.