Out-of-Bounds Read Vulnerability in MobilityDB PostgreSQL Extension
CVE-2026-102639
7.1HIGH
What is CVE-2026-102639?
MobilityDB versions up to 1.3.0 are susceptible to an out-of-bounds read vulnerability that is linked to improper WKB deserialization. This flaw enables unauthorized database users to initiate a Denial of Service (DoS) attack on the PostgreSQL backend by sending a crafted WKB payload with a negative length. The erroneous length causes memory corruption by bypassing necessary bounds checks due to the absence of signed validation, leading the memcpy function to operate with this corrupted length. This attack affects all sessions within the impacted PostgreSQL instance, which could lead to significant operational interruptions.
Affected Version(s)
MobilityDB 1.1.0 <= 1.1.2
MobilityDB 1.2.0 < 1.2.2
MobilityDB 1.3.0 < 1.3.1
