Integer Wraparound Vulnerability in PostgreSQL libpq Client Library
CVE-2025-12818

5.9MEDIUM

Key Information:

Vendor

PostgreSQL

Vendor
CVE Published:
13 November 2025

What is CVE-2025-12818?

An integer wraparound flaw in multiple functions of the PostgreSQL libpq client library may allow a malicious application input provider or network peer to exploit memory allocation issues. This vulnerability can lead to an undersized allocation, permitting out-of-bounds writes that can disrupt application stability, potentially resulting in segmentation faults. Users are encouraged to update to the latest versions to mitigate these risks.

Affected Version(s)

PostgreSQL 18 < 18.1

PostgreSQL 17 < 17.7

PostgreSQL 16 < 16.11

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The PostgreSQL project thanks Aleksey Solovev (Positive Technologies) for reporting this problem.
.
CVE-2025-12818 : Integer Wraparound Vulnerability in PostgreSQL libpq Client Library