CVE-2026-2005: PostgreSQL

High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Affected products

  • PostgreSQL PostgreSQL: from 14.0, before 14.21 (fixed in 14.21); from 15.0, before 15.16 (fixed in 15.16); from 16.0, before 16.12 (fixed in 16.12); from 17.0, before 17.8 (fixed in 17.8); from 18.0, before 18.2 (fixed in 18.2)

Published 2026-02-12. Last modified 2026-07-15.