Out-of-Bounds Read Vulnerability in MobilityDB PostgreSQL Extension
CVE-2026-102639

7.1HIGH

Key Information:

Vendor

Mobilitydb

Vendor
CVE Published:
29 September 2026

What is CVE-2026-102639?

MobilityDB versions up to 1.3.0 are susceptible to an out-of-bounds read vulnerability that is linked to improper WKB deserialization. This flaw enables unauthorized database users to initiate a Denial of Service (DoS) attack on the PostgreSQL backend by sending a crafted WKB payload with a negative length. The erroneous length causes memory corruption by bypassing necessary bounds checks due to the absence of signed validation, leading the memcpy function to operate with this corrupted length. This attack affects all sessions within the impacted PostgreSQL instance, which could lead to significant operational interruptions.

Affected Version(s)

MobilityDB 1.1.0 <= 1.1.2

MobilityDB 1.2.0 < 1.2.2

MobilityDB 1.3.0 < 1.3.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harsh Raj Singhania
.