CVE-2026-2006: PostgreSQL
High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.
Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Affected products
- PostgreSQL PostgreSQL: from 14.0, before 14.21 (fixed in 14.21); from 15.0, before 15.16 (fixed in 15.16); from 16.0, before 16.12 (fixed in 16.12); from 17.0, before 17.8 (fixed in 17.8); from 18.0, before 18.2 (fixed in 18.2)
Published 2026-02-12. Last modified 2026-07-15.