CVE 8.8 HIGH

PostgreSQL missing validation of multibyte character length executes arbitrary code_CVE-2026-2006

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

AI Analysis

Buffer overrun vulnerability in PostgreSQL due to missing validation of multibyte character length, allowing arbitrary code execution

Basic Information

ID CVE-2026-2006
Source PostgreSQL
Published Feb 12, 2026 at 13:00
Modified Feb 12, 2026 at 14:19

Affected Product

Vendor n/a
Product PostgreSQL
Version 18
Affected Versions n/a PostgreSQL 18
n/a PostgreSQL 17
n/a PostgreSQL 16
n/a PostgreSQL 15
n/a PostgreSQL 0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor PostgreSQL Global Development Group
Product PostgreSQL
Version 18.2, 17.8, 16.12, 15.16, 14.21

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.