CVE-2026-2005
EUVD-2026-618212.02.2026, 14:16
Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| postgresql | postgresql | 14.0 ≤ 𝑥 < 14.21 |
| postgresql | postgresql | 15.0 ≤ 𝑥 < 15.16 |
| postgresql | postgresql | 16.0 ≤ 𝑥 < 16.12 |
| postgresql | postgresql | 17.0 ≤ 𝑥 < 17.8 |
| postgresql | postgresql | 18.0 ≤ 𝑥 < 18.2 |
𝑥
= Vulnerable software versions
Debian Releases